PT-2019-6086 · Qemu+3 · Qemu+3

Riccardo Schirone

·

Publicado

2019-07-01

·

Atualizado

2024-06-15

·

CVE-2019-13164

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions 3.1 through 4.0.0
Description The issue is related to a security flaw in the qemu-bridge-helper.c function of the QEMU hardware emulator. This flaw can lead to an ACL bypass due to the lack of limitation on the network interface name size, which is obtained from bridge.conf or a --br=bridge option. The exploitation of this flaw may allow an attacker to gain unauthorized access to information, cause a denial of service, or impact the availability of information.
Recommendations For QEMU versions 3.1 through 4.0.0, consider restricting access to the qemu-bridge-helper.c function until a patch is available. As a temporary workaround, limit the network interface name size to the IFNAMSIZ size to prevent potential ACL bypass. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2496
ALT-PU-2019-2534
BDU:2021-05168
CVE-2019-13164
DLA-1927-1
DSA-4506-1
DSA-4512-1
OPENSUSE-SU-2019:2041-1
OPENSUSE-SU-2019:2059-1
OPENSUSE-SU-2019_2041-1
OPENSUSE-SU-2019_2059-1
OPENSUSE-SU-2024:11287-1
SUSE-SU-2019:14151-1
SUSE-SU-2019:2157-1
SUSE-SU-2019:2192-1
SUSE-SU-2019:2221-1
SUSE-SU-2019:2246-1
SUSE-SU-2019:2353-1
SUSE-SU-2019_14151-1
USN-4191-1
USN-4191-2

Produtos afetados

Alt Linux
Qemu
Suse
Ubuntu