Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 483216 (CVE-2013-2007) - <app-emulation/qemu-1.4.1 : Weak File Permissions (CVE-2013-2007)
Summary: <app-emulation/qemu-1.4.1 : Weak File Permissions (CVE-2013-2007)
Status: RESOLVED FIXED
Alias: CVE-2013-2007
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-09-01 00:02 UTC by GLSAMaker/CVETool Bot
Modified: 2013-09-02 18:20 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-09-01 00:02:43 UTC
CVE-2013-2007 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2007):
  The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started
  in daemon mode, uses weak permissions for certain files, which allows local
  users to read and write to these files.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-01 00:05:26 UTC
Also can affect Xen, but [1] says that this is really not a default configuration and requires a lot of work on the part of the systems administrator. Removing maintainers since they don't need to be CC'd. GLSA vote: no.

[1] http://www.openwall.com/lists/oss-security/2013/05/06/5
Comment 2 Sergey Popov gentoo-dev 2013-09-02 10:30:11 UTC
GLSA vote: no

Closing as noglsa.