Lucene search

K
f5F5F5:K31501591
HistoryDec 20, 2017 - 12:00 a.m.

K31501591 : QEMU vulnerability CVE-2017-15118

2017-12-2000:00:00
my.f5.com
17

9.4 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.6%

Security Advisory Description

A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS. (CVE-2017-15118)

Impact

There is no impact; F5 products are not affected by this vulnerability.

9.4 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.6%