PT-2019-4607 · Qemu+3 · Qemu+3

Michael Hanselmann

·

Published

2019-02-19

·

Updated

2023-02-12

·

CVE-2019-3812

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QEMU versions 2.10 through 3.1.0
Description The issue is related to an out-of-bounds read of up to 128 bytes in the i2c ddc() function, located in the hw/i2c/i2c-ddc.c file. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host, potentially revealing protected information.
Recommendations For QEMU versions 2.10 through 3.1.0, consider restricting access to the i2c ddc() function in the hw/i2c/i2c-ddc.c file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1973
ALT-PU-2019-1990
BDU:2020-00722
CVE-2019-3812
DSA-4454-1
DSA-4454-2
OPENSUSE-SU-2019:1405-1
OPENSUSE-SU-2019_1274-1
OPENSUSE-SU-2019_1405-1
SUSE-SU-2019:1238-1
SUSE-SU-2019:1239-1
USN-3923-1

Affected Products

Alt Linux
Qemu
Suse
Ubuntu