In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
References
Link | Resource |
---|---|
https://lists.gnu.org/archive/html/qemu-devel/2019-01/msg02324.html | Exploit Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2019/01/24/1 | Mailing List Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJMTVGDLA654HNCDGLCUEIP36SNJEKK7/ | Mailing List Release Notes Third Party Advisory |
https://security.netapp.com/advisory/ntap-20190411-0006/ | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:2166 | |
https://access.redhat.com/errata/RHSA-2019:2425 | |
https://access.redhat.com/errata/RHSA-2019:2553 |
Information
Published : 2019-03-21 09:01
Updated : 2019-08-06 10:15
NVD link : CVE-2019-6501
Mitre link : CVE-2019-6501
JSON object : View
Products Affected
fedoraproject
- fedora
qemu
- qemu