Buffer overflow in QEMU - CVE-2018-17962

 

Buffer overflow in QEMU - CVE-2018-17962

Published: November 21, 2018


Vulnerability identifier: #VU15996
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17962
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to buffer overflow in pcnet_receive in hw/net/pcnet.c when an incorrect integer data type is used. A remote attacker can supply specially crafted packets over the network, trigger memory corruption and crash the Qemu process.


Affected software

QEMU
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
qemu

How to mitigate CVE-2018-17962

Update to version 3.0.0.

QEMU - update to 3.0.0
qemu - update to 3.0.0-2.fc29

External References

Related Security Bulletins