CVE-2013-1922Qemu vulnerability

8 documents6 sources
Severity
3.3LOWNVD
OSV4.9
EPSS
0.1%
top 76.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 17

Description

qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.

CVSS vector

AV:L/AC:M/C:P/I:P/A:NExploitability: 3.4 | Impact: 4.9

Affected Packages4 packages

debiandebian/qemu< qemu 1.5.0+dfsg-1 (bookworm)
Debianqemu/qemu< 1.5.0+dfsg-1+3
debiandebian/xen< qemu 1.5.0+dfsg-1 (bookworm)
NVDxen/xen4.2.0, 4.2.1, 4.2.2+2

🔴Vulnerability Details

2
GHSA
GHSA-v7fq-6h69-259m: qemu-nbd in QEMU, as used in Xen 42022-05-17
OSV
CVE-2013-1922: qemu-nbd in QEMU, as used in Xen 42013-05-13

📋Vendor Advisories

2
Red Hat
kvm: qemu-nbd block format auto-detection vulnerability2013-04-15
Debian
CVE-2013-1922: qemu - qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk imag...2013

💬Community

3
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]2013-04-16
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability [fedora-all]2013-04-16
Bugzilla
CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability2013-03-19