QEMU 'net/slirp. c' insecure temporary File Creation Vulnerability
QEMU 'net/slirp. c' insecure temporary File Creation Vulnerability
Release date:
Updated on:
Affected Systems:
QEMU
Description:
Bugtraq id: 74809
CVE (CAN) ID: CVE-2015-4037
QEMU is an open source simulator software.
QEMU 2.3.0 in/net/slirp. c has a security vulnerability. Attackers with local access permissions exploit this vulnerability to execute symbolic link attacks and overwrite arbitrary files in the context of the affected application.
<* Source: Kurt Seifried ([email protected])
*>
Suggestion:
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wiki.qemu-project.org/download/qemu-2.3.0.tar.bz2
Linux getting started Tutorial: QEMU for Virtual Machine experience
Ubuntu 12.04 cannot find the Qemu command
Install QEMU + efi bios on Arch Linux
QEMU translation framework and debugging tools
QEMU code analysis: BIOS loading process
QEMU details: click here
QEMU: click here
This article permanently updates the link address: