Home→Descriptions→SA49431
| Secunia ID | |
| CVE-ID | |
| Release Date |
12 Jun 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
libguestfs 1.x |
| Where | |
| Impact |
Exposure of sensitive informationVulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote. |
| Description |
A security issue has been reported in libguestfs, which can be exploited by malicious, local users to disclose potentially sensitive information. The security issue is caused due to the "virt-edit" utility not keeping original file permissions when editing a file inside a virtual machine image, which results in world-readable permissions being set. The security issue is reported in version 1.16.4. Other versions may also be affected. |
| Solution |
Update to version 1.16.24. |
| Reported by |
Reported by Richard W.M. Jones in a Red Hat bug report. |
| Original Advisory |