Lucene search

K
nvd[email protected]NVD:CVE-2013-1922
HistoryMay 13, 2013 - 11:55 p.m.

CVE-2013-1922

2013-05-1323:55:01
CWE-264
web.nvd.nist.gov
8

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

31.5%

qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.

Affected configurations

Nvd
Node
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2
VendorProductVersionCPE
xenxen4.2.0cpe:2.3:o:xen:xen:4.2.0:*:*:*:*:*:*:*
xenxen4.2.1cpe:2.3:o:xen:xen:4.2.1:*:*:*:*:*:*:*
xenxen4.2.2cpe:2.3:o:xen:xen:4.2.2:*:*:*:*:*:*:*

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

31.5%