LWN.net Logo

qemu-kvm: privilege escalation

Package(s):qemu-kvm CVE #(s):CVE-2013-2231
Created:July 23, 2013 Updated:July 26, 2013
Description: From the Red Hat advisory:

An unquoted search path flaw was found in the way the QEMU Guest Agent service installation was performed on Windows. Depending on the permissions of the directories in the unquoted search path, a local, unprivileged user could use this flaw to have a binary of their choosing executed with SYSTEM privileges.

Alerts:
Red Hat RHSA-2013:1100-01 2013-07-22
Red Hat RHSA-2013:1101-01 2013-07-22
Oracle ELSA-2013-1100 2013-07-22
Scientific Linux SL-qemu-20130722 2013-07-22
CentOS CESA-2013:1100 2013-07-22
Mageia MGASA-2013-0235 2013-07-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds