World-readable permissions set by virt-edit in libguestfs before 1.18.0 may expose sensitive information to local guest users.

World-readable permissions set by virt-edit in libguestfs before 1.18.0 may expose sensitive information to local guest users.

CVE-2012-2690 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

Learn more about our User Device Pen Test.