oss-sec mailing list archives

CVE-2013-2231 -- qemu: qemu-ga win32 service unquoted search path


From: Petr Matousek <pmatouse () redhat com>
Date: Mon, 22 Jul 2013 15:22:40 +0200

An unquoted search path flaw was found in the way qemu guest agent
service for Windows was installed into the system.

A local unprivileged user could use this flaw to increase their
privileges.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=980757
http://cwe.mitre.org/data/definitions/428.html

-- 
Petr Matousek / Red Hat Security Response Team


Current thread: