CVE-2012-2690

low
Published 2012-06-29 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.1

Description

virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1:1.18.0-1
sid Fixed 1:1.18.0-1
forky Fixed 1:1.18.0-1
bullseye Fixed 1:1.18.0-1
bookworm Fixed 1:1.18.0-1

Application impact

VendorProductVersionsFixed
libguestfslibguestfs{"endIncluding":"1.17.43"}
libguestfslibguestfs1.16.0
libguestfslibguestfs1.16.1
libguestfslibguestfs1.16.2
libguestfslibguestfs1.16.3
libguestfslibguestfs1.16.4
libguestfslibguestfs1.16.5
libguestfslibguestfs1.16.6
libguestfslibguestfs1.16.7
libguestfslibguestfs1.16.8
libguestfslibguestfs1.16.9
libguestfslibguestfs1.16.10
libguestfslibguestfs1.16.11
libguestfslibguestfs1.16.12
libguestfslibguestfs1.16.13
libguestfslibguestfs1.16.14
libguestfslibguestfs1.16.15
libguestfslibguestfs1.16.16
libguestfslibguestfs1.16.17
libguestfslibguestfs1.16.18
libguestfslibguestfs1.16.19
libguestfslibguestfs1.16.20
libguestfslibguestfs1.16.21
libguestfslibguestfs1.16.22
libguestfslibguestfs1.16.23
libguestfslibguestfs1.16.24
libguestfslibguestfs1.16.25
libguestfslibguestfs1.16.26
libguestfslibguestfs1.17.0
libguestfslibguestfs1.17.1
libguestfslibguestfs1.17.2
libguestfslibguestfs1.17.3
libguestfslibguestfs1.17.4
libguestfslibguestfs1.17.5
libguestfslibguestfs1.17.6
libguestfslibguestfs1.17.7
libguestfslibguestfs1.17.8
libguestfslibguestfs1.17.9
libguestfslibguestfs1.17.10
libguestfslibguestfs1.17.11
libguestfslibguestfs1.17.12
libguestfslibguestfs1.17.13
libguestfslibguestfs1.17.14
libguestfslibguestfs1.17.15
libguestfslibguestfs1.17.16
libguestfslibguestfs1.17.17
libguestfslibguestfs1.17.18
libguestfslibguestfs1.17.19
libguestfslibguestfs1.17.20
libguestfslibguestfs1.17.21
libguestfslibguestfs1.17.22
libguestfslibguestfs1.17.23
libguestfslibguestfs1.17.24
libguestfslibguestfs1.17.25
libguestfslibguestfs1.17.26
libguestfslibguestfs1.17.27
libguestfslibguestfs1.17.28
libguestfslibguestfs1.17.29
libguestfslibguestfs1.17.30
libguestfslibguestfs1.17.31
libguestfslibguestfs1.17.32
libguestfslibguestfs1.17.33
libguestfslibguestfs1.17.34
libguestfslibguestfs1.17.35
libguestfslibguestfs1.17.36
libguestfslibguestfs1.17.37
libguestfslibguestfs1.17.38
libguestfslibguestfs1.17.39
libguestfslibguestfs1.17.40
libguestfslibguestfs1.17.41
libguestfslibguestfs1.17.42

References

CWEs

CWE-255

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.