Lucene search

K
cvelistRedhatCVELIST:CVE-2017-2630
HistoryJul 27, 2018 - 6:00 p.m.

CVE-2017-2630

2018-07-2718:00:00
CWE-121
redhat
www.cve.org

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%

A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server’s response to a ‘NBD_OPT_LIST’ request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.

CNA Affected

[
  {
    "product": "Qemu:",
    "vendor": "QEMU",
    "versions": [
      {
        "status": "affected",
        "version": "2.9"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

7.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%