Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gq4-xvgv-m3gv

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

EPSS

Процентиль: 13%
0.00044
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

redhat
больше 11 лет назад

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

CVSS3: 7.8
nvd
около 4 лет назад

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

CVSS3: 7.8
debian
около 4 лет назад

An user able to alter the savevm data (either on the disk or over the ...

CVSS3: 7.8
fstec
около 12 лет назад

Уязвимость функционала savevm эмулятора аппаратного обеспечения QEMU, связанная с небезопасным управлением привилегиями, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00044
Низкий

7.8 High

CVSS3

Дефекты

CWE-269