CVE-2012-2690
Publication date 29 June 2012
Last updated 24 July 2024
Ubuntu priority
virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.
Status
Package | Ubuntu Release | Status |
---|---|---|
libguestfs | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
libguestfs |
References
Other references
- https://www.redhat.com/archives/libguestfs/2012-February/msg00033.html
- https://bugzilla.redhat.com/show_bug.cgi?id=788642
- http://www.openwall.com/lists/oss-security/2012/06/11/1
- http://www.openwall.com/lists/oss-security/2012/06/11/5
- https://rhn.redhat.com/errata/RHSA-2012-0774.html
- https://www.cve.org/CVERecord?id=CVE-2012-2690