CVE-2012-2690: Libguestfs
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.
Affected products
- Libguestfs Libguestfs: up to and including 1.17.43; version 1.16.0 only; version 1.16.1 only; version 1.16.2 only; version 1.16.3 only; version 1.16.4 only; …
Published 2012-06-29. Last modified 2026-06-16.