Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20485

Опубликовано: 19 мар. 2020
Источник: debian
EPSS Низкий

Описание

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed6.0.0-2package
libvirtno-dsabusterpackage
libvirtno-dsastretchpackage
libvirtnot-affectedjessiepackage

Примечания

  • https://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=a663a860819287e041c3de672aad1d8543098ecc (v6.0.0-rc1)

  • Disputed upstream: https://listman.redhat.com/archives/libvir-list/2019-December/msg00313.html

EPSS

Процентиль: 43%
0.00203
Низкий

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.8
redhat
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
nvd
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
github
около 3 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

oracle-oval
около 5 лет назад

ELSA-2020-5674: libvirt security update (IMPORTANT)

EPSS

Процентиль: 43%
0.00203
Низкий