PT-2016-2679 · Qemu+3 · Qemu+3

Li Qiang

·

Publicado

2016-05-30

·

Atualizado

2024-06-15

·

CVE-2016-5105

CVSS v3.1

4.4

Média

VetorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to the megasas dcmd cfg read function in the hw/scsi/megasas.c file of QEMU, specifically when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support. This function uses an uninitialized variable, allowing local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Use of Uninitialized Resource

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1043
BDU:2016-02071
CVE-2016-5105
DLA-1599-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2016_2497-1
OPENSUSE-SU-2016_2642-1
OPENSUSE-SU-2024:10233-1
SUSE-SU-2016:2093-1
SUSE-SU-2016:2100-1
SUSE-SU-2016:2533-1
SUSE-SU-2016:2589-1
SUSE-SU-2016:2628-1
SUSE-SU-2016:2781-1
USN-3047-1
USN-3047-2

Produtos afetados

Alt Linux
Qemu
Suse
Ubuntu