Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6778

Опубликовано: 11 янв. 2019
Источник: redhat
CVSS3: 7.8

Описание

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

A heap buffer overflow issue was found in the SLiRP networking implementation of the QEMU emulator. It occurs in tcp_emu() routine while emulating the Identification protocol and copying message data to a socket buffer. A user or process could use this flaw to crash the QEMU process on the host resulting in a DoS or potentially executing arbitrary code with privileges of the QEMU process.

Отчет

Red Hat OpenStack Platform:
This flaw impacts KVM user-mode or SLIRP networking, which is not used in Red Hat OpenStack. Updating is recommended, however Red Hat OpenStack installs are not vulnerable to the described flaw due to the vulnerable feature not being used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat OpenStack Platform 8 (Liberty)qemu-kvm-rhevOut of support scope
Red Hat OpenStack Platform 9 (Mitaka)qemu-kvm-rhevOut of support scope
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2019:289224.09.2019
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2019:188329.07.2019
Red Hat OpenStack Platform 10.0 (Newton)qemu-kvm-rhevFixedRHSA-2019:242509.08.2019
Red Hat OpenStack Platform 13.0 (Queens)qemu-kvm-rhevFixedRHSA-2019:242509.08.2019
Red Hat OpenStack Platform 14.0 (Rocky)qemu-kvm-rhevFixedRHSA-2019:242509.08.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1664205QEMU: slirp: heap buffer overflow in tcp_emu()

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

CVSS3: 7.8
nvd
около 6 лет назад

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

CVSS3: 7.8
debian
около 6 лет назад

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer ove ...

CVSS3: 7.8
github
около 3 лет назад

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

oracle-oval
почти 6 лет назад

ELSA-2019-1883: qemu-kvm security update (IMPORTANT)

7.8 High

CVSS3