Security Advisory

CVE-2010-3851

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-11-04 17:00:00
Last updated 2024-08-07 03:26:11
Assigner redhat
State PUBLISHED

Description

libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.