libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-11-04 11:00
Updated : 2011-08-26 20:44
NVD link : CVE-2010-3851
Mitre link : CVE-2010-3851
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
matthew_booth
- virt-v2v
richard_jones
- virt-inspector
libguestfs
- libguestfs