CVE Database
/

CVE-2020-1711

Back to search

CVE-2020-1711

Published: Feb 11, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

7.7

HIGH

Description

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.

VendorProductVersions

Red Hat

QEMU

affected
All qemu versions 2.12.0 before 4.2.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

High

References

USN-4283-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2020:0669
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0773
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0730
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0731
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0468
vendor-advisory
x_refsource_SUSE
GLSA-202005-02
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now