Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Qemu 不安全临时文件漏洞
Vulnerability Description
QEMU(又名Quick Emulator)是法国程序员法布里斯-贝拉(Fabrice Bellard)所研发的一套模拟处理器软件。该软件具有速度快、跨平台等特点。 Qemu 1.0版本中的bdrv_open函数中存在漏洞,该漏洞源于未正确处理mkstemp函数的失效。当在snapshot节点时,本地攻击者可利用该漏洞借助在未指定临时文件中的符号链接攻击重写或读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A