cbcvebase.
CVE-2008-1945
published 2008-08-08

CVE-2008-1945: QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat…

low2.1CVSS 3.1
AVLACLAuNCPINAN
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 0.9.1-5 (bookworm)qemu 0.9.1-5 (bookworm)
opensuseopensuse
opensuseopensuse
opensuseopensuse
qemuqemu
qemuqemu>= 0 < 0.9.1-50.9.1-5
qemuqemu>= 0 < 0.9.1-50.9.1-5
qemuqemu>= 0 < 0.9.1-50.9.1-5
qemuqemu>= 0 < 0.9.1-50.9.1-5
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvd2.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW