Comment 72 for bug 1449062

Revision history for this message
Hemanth Makkapati (hemanth-makkapati) wrote : Re: qemu-img calls need to be restricted by ulimit (CVE-2015-5162)

It's just a theory (credits to Brian Rosmaita) at this point, but looks like "qemu-img convert" will try to infer the format of input image if "-f" is not provided. So, "qemu-img convert" may be susceptible to the same attack. Any thoughts?