English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

libguestfs "virt-edit" File Permissions Security Issue


Secunia ID

SA49431

CVE-ID

CVE-2012-2690

Release Date

12 Jun 2012

Criticality

Not Critical

Solution Status

Vendor Patch

Software

libguestfs 1.x

Where

Local system

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

A security issue has been reported in libguestfs, which can be exploited by malicious, local users to disclose potentially sensitive information.

The security issue is caused due to the "virt-edit" utility not keeping original file permissions when editing a file inside a virtual machine image, which results in world-readable permissions being set.

The security issue is reported in version 1.16.4. Other versions may also be affected.

Solution

Update to version 1.16.24.

Reported by

Reported by Richard W.M. Jones in a Red Hat bug report.

Original Advisory

https://bugzilla.redhat.com/show_bug.cgi?id=788642