LWN.net Logo

libguestfs: unintended file access

Package(s):libguestfs CVE #(s):CVE-2012-2690
Created:June 20, 2012 Updated:July 10, 2012
Description: From the Red Hat advisory:

It was found that editing files with virt-edit left said files in a world-readable state (and did not preserve the file owner or Security-Enhanced Linux context). If an administrator on the host used virt-edit to edit a file inside a guest, the file would be left with world-readable permissions. This could lead to unprivileged guest users accessing files they would otherwise be unable to.

Alerts:
Red Hat RHSA-2012:0774-04 2012-06-20
Oracle ELSA-2012-0774 2012-07-02
Scientific Linux SL-libg-20120709 2012-07-09
CentOS CESA-2012:0774 2012-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds