Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9824

Опубликовано: 03 июн. 2019
Источник: debian
EPSS Низкий

Описание

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:3.1+dfsg-6package
qemu-kvmremovedpackage
slirp4netnsfixed0.3.1-1package
slirp4netnsfixed0.2.3-1busterpackage

Примечания

  • https://lists.gnu.org/archive/html/qemu-devel/2019-03/msg01871.html

  • https://www.openwall.com/lists/oss-security/2019/03/18/1

  • https://github.com/qemu/qemu/commit/d3222975c7d6cda9e25809dea05241188457b113

  • https://github.com/rootless-containers/slirp4netns/security/advisories/GHSA-vp7q-v36g-7vq7

EPSS

Процентиль: 30%
0.00106
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

CVSS3: 2.8
redhat
больше 6 лет назад

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

CVSS3: 5.5
nvd
около 6 лет назад

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

github
около 3 лет назад

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

oracle-oval
почти 6 лет назад

ELSA-2019-2078: qemu-kvm security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 30%
0.00106
Низкий