QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
| Software | From | Fixed in |
|---|---|---|
| qemu / qemu | 0.9.0 | 0.9.0.x |
| opensuse / opensuse | 11.1 | 11.1.x |
| opensuse / opensuse | 11.0 | 11.0.x |
| opensuse / opensuse | 10.3 | 10.3.x |
| suse / linux_enterprise_server | 11 | 11.x |
| suse / linux_enterprise_server | 10 | 10.x |
| debian / debian_linux | 5.0 | 5.0.x |
| debian / debian_linux | 4.0 | 4.0.x |
| canonical / ubuntu_linux | 8.10 | 8.10.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |
| redhat / enterprise_linux_server | 5.0 | 5.0.x |
| redhat / enterprise_linux_workstation | 5.0 | 5.0.x |
| redhat / enterprise_linux_desktop | 5.0 | 5.0.x |
| redhat / enterprise_linux_eus | 5.2 | 5.2.x |