Описание
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | released | 1:2.11+dfsg-1ubuntu7.8 |
cosmic | released | 1:2.12+dfsg-3ubuntu8.1 |
devel | released | 1:2.12+dfsg-3ubuntu9 |
disco | released | 1:2.12+dfsg-3ubuntu9 |
eoan | released | 1:2.12+dfsg-3ubuntu9 |
esm-infra-legacy/trusty | not-affected | 2.0.0+dfsg-2ubuntu1.44 |
esm-infra/bionic | not-affected | 1:2.11+dfsg-1ubuntu7.8 |
esm-infra/focal | not-affected | 1:2.12+dfsg-3ubuntu9 |
esm-infra/xenial | not-affected | 1:2.5+dfsg-5ubuntu10.33 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE |
Показывать по
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c i ...
5 Medium
CVSS2
7.5 High
CVSS3