EulerOS Virtualization 2.5.1 : qemu-kvm (EulerOS-SA-2018-1321)
High Nessus Plugin ID 118366
SynopsisThe remote EulerOS Virtualization host is missing a security update.
DescriptionAccording to the version of the qemu-kvm packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerability :
- Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.(CVE-2016-9602)
Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected qemu-kvm package.