Security Advisory

CVE-2011-2527

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-06-21 15:00:00
Last updated 2024-08-06 23:00:34
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.