CVE-2012-2690

low
Published 2012-06-29 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2690

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/49545

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/49431

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:1.18.0-1
debian debianbullseyefixed1:1.18.0-1
debian debianforkyfixed1:1.18.0-1
debian debiansidfixed1:1.18.0-1
debian debiantrixiefixed1:1.18.0-1

Application impact

VendorProductVersionsFixed
libguestfslibguestfs{"endIncluding":"1.17.43"}
libguestfslibguestfs1.16.0
libguestfslibguestfs1.16.1
libguestfslibguestfs1.16.2
libguestfslibguestfs1.16.3
libguestfslibguestfs1.16.4
libguestfslibguestfs1.16.5
libguestfslibguestfs1.16.6
libguestfslibguestfs1.16.7
libguestfslibguestfs1.16.8
libguestfslibguestfs1.16.9
libguestfslibguestfs1.16.10
libguestfslibguestfs1.16.11
libguestfslibguestfs1.16.12
libguestfslibguestfs1.16.13
libguestfslibguestfs1.16.14
libguestfslibguestfs1.16.15
libguestfslibguestfs1.16.16
libguestfslibguestfs1.16.17
libguestfslibguestfs1.16.18
libguestfslibguestfs1.16.19
libguestfslibguestfs1.16.20
libguestfslibguestfs1.16.21
libguestfslibguestfs1.16.22
libguestfslibguestfs1.16.23
libguestfslibguestfs1.16.24
libguestfslibguestfs1.16.25
libguestfslibguestfs1.16.26
libguestfslibguestfs1.17.0
libguestfslibguestfs1.17.1
libguestfslibguestfs1.17.2
libguestfslibguestfs1.17.3
libguestfslibguestfs1.17.4
libguestfslibguestfs1.17.5
libguestfslibguestfs1.17.6
libguestfslibguestfs1.17.7
libguestfslibguestfs1.17.8
libguestfslibguestfs1.17.9
libguestfslibguestfs1.17.10
libguestfslibguestfs1.17.11
libguestfslibguestfs1.17.12
libguestfslibguestfs1.17.13
libguestfslibguestfs1.17.14
libguestfslibguestfs1.17.15
libguestfslibguestfs1.17.16
libguestfslibguestfs1.17.17
libguestfslibguestfs1.17.18
libguestfslibguestfs1.17.19
libguestfslibguestfs1.17.20
libguestfslibguestfs1.17.21
libguestfslibguestfs1.17.22
libguestfslibguestfs1.17.23
libguestfslibguestfs1.17.24
libguestfslibguestfs1.17.25
libguestfslibguestfs1.17.26
libguestfslibguestfs1.17.27
libguestfslibguestfs1.17.28
libguestfslibguestfs1.17.29
libguestfslibguestfs1.17.30
libguestfslibguestfs1.17.31
libguestfslibguestfs1.17.32
libguestfslibguestfs1.17.33
libguestfslibguestfs1.17.34
libguestfslibguestfs1.17.35
libguestfslibguestfs1.17.36
libguestfslibguestfs1.17.37
libguestfslibguestfs1.17.38
libguestfslibguestfs1.17.39
libguestfslibguestfs1.17.40
libguestfslibguestfs1.17.41
libguestfslibguestfs1.17.42

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.