Lucene search

K
redosRedosROS-20240917-03
HistorySep 17, 2024 - 12:00 a.m.

ROS-20240917-03

2024-09-1700:00:00
redos.red-soft.ru
qemu
hardware emulator
resource consumption
unauthorized access
denial of service
crafted file
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

A vulnerability in the QEMU hardware emulator info command is related to uncontrolled consumption of
resources. Exploitation of the vulnerability could allow an attacker to gain access to sensitive data,
compromise their integrity, and cause a denial of service by using a specially crafted file
images

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64qemu< 7.2.13-1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High