Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
References
Configurations
History
No history.
Information
Published : 2018-04-26 19:29
Updated : 2024-11-21 03:01
NVD link : CVE-2016-9602
Mitre link : CVE-2016-9602
CVE.ORG link : CVE-2016-9602
JSON object : View
Products Affected
debian
- debian_linux
qemu
- qemu
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')