CVE-2013-1922
published 2013-05-13CVE-2013-1922: qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read…
PriorityP413low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.34%
26.9th percentile
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1.5.0+dfsg-1 (bookworm) | qemu 1.5.0+dfsg-1 (bookworm) |
| debian | xen | < qemu 1.5.0+dfsg-1 (bookworm) | qemu 1.5.0+dfsg-1 (bookworm) |
| qemu | qemu | >= 0 < 1.5.0+dfsg-1 | 1.5.0+dfsg-1 |
| qemu | qemu | >= 0 < 1.5.0+dfsg-1 | 1.5.0+dfsg-1 |
| qemu | qemu | >= 0 < 1.5.0+dfsg-1 | 1.5.0+dfsg-1 |
| qemu | qemu | >= 0 < 1.5.0+dfsg-1 | 1.5.0+dfsg-1 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v7fq-6h69-259m: qemu-nbd in QEMU, as used in Xen 4
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2013-1922 [MEDIUM] GHSA-v7fq-6h69-259m: qemu-nbd in QEMU, as used in Xen 4
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
OSV
CVE-2013-1922: qemu-nbd in QEMU, as used in Xen 4
osv·2013-05-13·CVSS 4.9
CVE-2013-1922 [MEDIUM] CVE-2013-1922: qemu-nbd in QEMU, as used in Xen 4
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Red Hat
kvm: qemu-nbd block format auto-detection vulnerability
vendor_redhat·2013-04-15·CVSS 4.9
CVE-2013-1922 [MEDIUM] kvm: qemu-nbd block format auto-detection vulnerability
kvm: qemu-nbd block format auto-detection vulnerability
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Statement: Not vulnerable.
This issue does not affect versions of kvm and xen packages as shipped with Red Hat Enterprise Linux 5. This issue does not affect versions of qemu-kvm packages as shipped with Red Hat Enterprise Linux 5 and 6.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-1922: qemu - qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk imag...
vendor_debian·2013·CVSS 4.9
CVE-2013-1922 [MEDIUM] CVE-2013-1922: qemu - qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk imag...
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Scope: local
bookworm: resolved (fixed in 1.5.0+dfsg-1)
bullseye: resolved (fixed in 1.5.0+dfsg-1)
forky: resolved (fixed in 1.5.0+dfsg-1)
sid: resolved (fixed in 1.5.0+dfsg-1)
trixie: resolved (fixed in 1.5.0+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
bugzilla·2013-04-16·CVSS 3.3
CVE-2013-1922 [LOW] CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
bugzilla·2013-04-16·CVSS 3.3
CVE-2013-1922 [LOW] CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability
bugzilla·2013-03-19·CVSS 4.9
CVE-2013-1922 [MEDIUM] CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability
A security flaw was found in the way qemu-nbd, the QEMU Disk Network Block Device server tool of QEMU, performed detection of image formats (the image format has been previously autodetected). A guest operating system administrator could write a header to particular raw disk image format, describing another format than original one for that disk image, leading to scenario in which after restart of that guest, QEMU would detect new format of the image, and could allow the guest to read any file on the host if QEMU was sufficiently privileged.
A different vulnerability that CVE-2008-2004.
Discussion:
Acknowledgements:
This issue was found by Daniel Berrange of Red Hat.
---
Created attachment 712650
P
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103621.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103637.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104036.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.openwall.com/lists/oss-security/2013/04/15/3http://www.openwall.com/lists/oss-security/2013/04/16/2http://www.securitytracker.com/id/1028426http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103621.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103637.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/104036.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.openwall.com/lists/oss-security/2013/04/15/3http://www.openwall.com/lists/oss-security/2013/04/16/2http://www.securitytracker.com/id/1028426
2013-05-13
Published