Cybertrion Systems

[2/5] QEMU “drive_init()” Disk Format Security Bypass

May 8th, 2008 by
[2/5] QEMU “drive_init()” Disk Format Security Bypass

:A vulnerability has been reported in QEMU, which can be exploited by malicious, local users to bypass certain security restrictions.The vulnerability is caused due to the "drive_init()" function in vl.c determining the format of a disk from data contained in the disk’s header. This can be exploited by a malicious user in a guest system to e.g. read arbitrary files on the host by writing a fake header to a raw formatted disk image.The vulnerability is reported in version 0.9.1. Other versions may also be affected.Solution:Fixed in the SVN repository.http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=4277Provided and/or discovered by:The vendor credits Avi Kivity.Original Advisory:http://lists.gnu.org/archive/html/qemu-devel/2008-04/msg00675.html

Original post by nitish

[2/5] QEMU “drive_init()” Disk Format Security Bypass

Related Articles:
  • [1/5] Fedora update for qemu
  • [3/5] Debian update for qemu
  • [3/5] WinUAE Floppy Disk Image File Loading Buffer Overflow
  • [3/5] QEMU Various Vulnerabilities
  • [4/5] Perdition IMAP Server Format String Vulnerability


  • Posted in Advisories - Exploits | | [2/5] QEMU “drive_init()” Disk Format Security Bypass

    << [2/5] Sun Ray Server Software Kiosk Mode Vulnerability | [3/5] Sun Java System Web Server / Application Server JSP Information Disclosure >>