CVE-2018-16867 | QEMU up to 3.0.x Media Transfer Protocol hw/usb/dev-mtp.c usb_mtp_write_data path traversal (USN-3923-1 / Nessus ID 209571)
A vulnerability was found in QEMU up to 3.0.x. It has been declared as critical. This vulnerability affects the function usb_mtp_write_data of the file hw/usb/dev-mtp.c of the component Media Transfer Protocol. The manipulation leads to path traversal.
This vulnerability was named CVE-2018-16867. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.