CVE-2012-2690

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
29/06/2012
Last modified:
11/04/2025

Description

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libguestfs:libguestfs:*:*:*:*:*:*:*:* 1.17.43 (including)
cpe:2.3:a:libguestfs:libguestfs:1.16.0:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.1:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.2:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.3:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.4:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.5:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.6:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.7:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.8:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.9:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.10:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.11:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.12:*:*:*:*:*:*:*
cpe:2.3:a:libguestfs:libguestfs:1.16.13:*:*:*:*:*:*:*