Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12247

Опубликовано: 07 янв. 2019
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable

Отчет

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 6virtio-winNot affected
Red Hat Enterprise Linux 7qemu-guest-agentNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 7virtio-winNot affected
Red Hat Enterprise Linux 8qemu-kvmNot affected
Red Hat Enterprise Linux 8virtio-winNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1712834QEMU: qemu-guest-agent: integer overflow while running guest-exec command

EPSS

Процентиль: 67%
0.00528
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable

CVSS3: 7.5
nvd
больше 6 лет назад

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable

CVSS3: 7.5
debian
больше 6 лет назад

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files d ...

CVSS3: 7.5
github
больше 3 лет назад

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables.

EPSS

Процентиль: 67%
0.00528
Низкий

3.8 Low

CVSS3