CVE-2018-16867Race Condition in Qemu

CWE-362Race Condition9 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 65.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 13

Description

A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.1 | Impact: 6.0

Affected Packages4 packages

debiandebian/qemu< qemu 1:3.1+dfsg-1 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.45+2
NVDqemu/qemu3.0.0+1

Also affects: Fedora 29, Ubuntu Linux 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6ch3-xhrw-w89m: A flaw was found in qemu Media Transfer Protocol (MTP) before version 32022-05-13
OSV
qemu vulnerabilities2019-03-27
OSV
CVE-2018-16867: A flaw was found in qemu Media Transfer Protocol (MTP) before version 32018-12-12

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2019-03-27
Red Hat
QEMU: dev-mtp: path traversal in usb_mtp_write_data of the Media Transfer Protocol (MTP)2018-12-03
Debian
CVE-2018-16867: qemu - A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A p...2018

💬Community

2
Bugzilla
CVE-2018-16867 qemu: path traversal in usb_mtp_write_data in hw/usb/dev-mtp.c of the Media Transfer Protocol (MTP) [fedora-all]2018-12-06
Bugzilla
CVE-2018-16867 QEMU: dev-mtp: path traversal in usb_mtp_write_data of the Media Transfer Protocol (MTP)2018-11-29