Libguestfs vulnerabilities
6 known vulnerabilities affecting libguestfs/libguestfs.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5LOW1
Vulnerabilities
Page 1 of 1
CVE-2022-2211MEDIUMCVSS 6.5vnone2022-07-12
CVE-2022-2211 [MEDIUM] CVE-2022-2211: A vulnerability was found in libguestfs
A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor.
cvelistv5osv
CVE-2013-2124MEDIUMCVSS 4.3v1.20.0v1.20.1+47 more2014-05-27
CVE-2013-2124 [MEDIUM] CVE-2013-2124: Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
nvdosv
CVE-2013-4419MEDIUMCVSS 6.8≥ 1.20.0, ≤ 1.20.12≥ 1.22.0, ≤ 1.22.72013-11-05
CVE-2013-4419 [MEDIUM] CWE-264 CVE-2013-4419: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --liste
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance
nvdosv
CVE-2011-4127MEDIUMCVSS 4.6≥ 0, < 1:1.14.8-12012-07-03
CVE-2011-4127 [MEDIUM] CVE-2011-4127: The Linux kernel before 3
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
osv
CVE-2012-2690LOWCVSS 2.1≤ 1.17.43v1.16.0+69 more2012-06-29
CVE-2012-2690 [LOW] CWE-255 CVE-2012-2690: virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and s
virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.
nvdosv
CVE-2010-3851MEDIUMCVSS 4.7≤ 1.5.22v1.5.0+21 more2010-11-04
CVE-2010-3851 [MEDIUM] CWE-200 CVE-2010-3851: libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other
libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
nvd