CVE-2012-2652 PUBLISHED CVSS 4.400000095367432 MEDIUM

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

EPSS 0.07% · 20.0th percentile

Risk Scores

CVSS v2.0
4.400000095367432
EPSS Score
0.07%
20.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
qemuqemu1.0

Timeline

References

Open in Interactive Console →