Описание
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:2.11+dfsg-1ubuntu7.20 |
| cosmic | ignored | end of life |
| devel | released | 1:4.2-1ubuntu1 |
| disco | released | 1:3.1+dfsg-2ubuntu3.6 |
| eoan | released | 1:4.0+dfsg-0ubuntu9.1 |
| esm-infra-legacy/trusty | released | 2.0.0+dfsg-2ubuntu1.47 |
| esm-infra/bionic | released | 1:2.11+dfsg-1ubuntu7.20 |
| esm-infra/xenial | released | 1:2.5+dfsg-5ubuntu10.42 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| precise/esm | not-affected | code does not exist |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a netw ...
qemu-bridge-helper.c in QEMU 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Уязвимость функции qemu-bridge-helper.c эмулятора аппаратного обеспечения QEMU, связанная с недостатках элементов безопасности, позволяющая нарушителю получить несанкционированный доступ к информации, вызвать отказ в обслуживании или оказать воздействие на доступность информации
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3