Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17962

Опубликовано: 26 сент. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

An integer overflow issue was found in the AMD PC-Net II NIC emulation in QEMU. It could occur while receiving packets, if the size value was greater than INT_MAX. Such overflow would lead to stack buffer overflow issue. A user inside guest could use this flaw to crash the QEMU process resulting in DoS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2019:289224.09.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1636773QEMU: pcnet: integer overflow leads to buffer overflow

EPSS

Процентиль: 71%
0.00711
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

CVSS3: 7.5
nvd
больше 6 лет назад

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

CVSS3: 7.5
debian
больше 6 лет назад

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because ...

CVSS3: 7.5
github
около 3 лет назад

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

oracle-oval
больше 5 лет назад

ELSA-2019-2892: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 71%
0.00711
Низкий

6.5 Medium

CVSS3