Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-35505

Опубликовано: 28 мая 2021
Источник: ubuntu
Приоритет: low
CVSS2: 2.1
CVSS3: 4.4

Описание

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

РелизСтатусПримечание
bionic

released

1:2.11+dfsg-1ubuntu7.37
devel

released

1:6.0+dfsg-1~ubuntu3
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

1:2.11+dfsg-1ubuntu7.37
esm-infra/focal

released

1:4.2-3ubuntu6.17
esm-infra/xenial

needed

focal

released

1:4.2-3ubuntu6.17
groovy

released

1:5.0-5ubuntu9.9
hirsute

released

1:5.2+dfsg-9ubuntu3.1
impish

released

1:6.0+dfsg-1~ubuntu3

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

2.1 Low

CVSS2

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.2
redhat
около 5 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
nvd
больше 4 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
msrc
больше 4 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
debian
больше 4 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bu ...

CVSS3: 4.4
github
больше 3 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

2.1 Low

CVSS2

4.4 Medium

CVSS3