PT-2018-3378 · Qemu+3 · Qemu+3
Moguofang
·
Publicado
2018-11-08
·
Atualizado
2019-06-06
·
CVE-2018-18954
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
QEMU versions prior to 3.1
Description:
The issue is related to the pnv lpc do eccb function in the QEMU emulator, specifically in the hw/ppc/pnv lpc.c file. It involves a buffer data boundary read issue. Exploitation of this issue could allow an attacker to cause a denial of service and gain unauthorized access to PowerNV memory.
Recommendations:
For QEMU versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pnv lpc do eccb function to minimize the risk of exploitation.
Correção
Out of bounds Read
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Qemu
Suse
Ubuntu