PT-2018-3378 · Qemu+3 · Qemu+3

Moguofang

·

Publicado

2018-11-08

·

Atualizado

2019-06-06

·

CVE-2018-18954

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: QEMU versions prior to 3.1
Description: The issue is related to the pnv lpc do eccb function in the QEMU emulator, specifically in the hw/ppc/pnv lpc.c file. It involves a buffer data boundary read issue. Exploitation of this issue could allow an attacker to cause a denial of service and gain unauthorized access to PowerNV memory.
Recommendations: For QEMU versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pnv lpc do eccb function to minimize the risk of exploitation.

Correção

Out of bounds Read

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2870
BDU:2020-00704
CVE-2018-18954
DSA-4454-1
DSA-4454-2
OPENSUSE-SU-2019:0254-1
OPENSUSE-SU-2019_0254-1
OPENSUSE-SU-2019_1074-1
SUSE-SU-2019:0423-1
SUSE-SU-2019:0435-1
SUSE-SU-2019:0582-1
USN-3826-1

Produtos afetados

Alt Linux
Qemu
Suse
Ubuntu