4.7

CVE-2010-3851

libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.

Data is provided by the National Vulnerability Database (NVD)
LibguestfsLibguestfs Version <= 1.5.22
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.0
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.1
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.2
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.3
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.4
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.5
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.6
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.7
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.8
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.9
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.10
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.11
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.12
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.13
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.14
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.15
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.16
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.17
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.18
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.19
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.20
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
LibguestfsLibguestfs Version1.5.21
   Matthew BoothVirt-v2v
   Richard JonesVirt-inspector Version <= 1.5.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.262
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.