Lucene search

K
nvd[email protected]NVD:CVE-2008-2004
HistoryMay 12, 2008 - 10:20 p.m.

CVE-2008-2004

2008-05-1222:20:00
CWE-200
web.nvd.nist.gov
8

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0.001

Percentile

31.5%

The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.

Affected configurations

Nvd
Node
qemuqemuMatch0.9.1
VendorProductVersionCPE
qemuqemu0.9.1cpe:2.3:a:qemu:qemu:0.9.1:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0.001

Percentile

31.5%