5

CVE-2020-10761

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version < 5.0.1
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 8.0 SwEdition advanced_virtualization
Opensuse ≫ Leap Version 15.2
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.756
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://security.gentoo.org/glsa/202011-09
Third Party Advisory
https://usn.ubuntu.com/4467-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10761
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20200731-0001/
Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/06/09/1
Patch
Third Party Advisory
Mailing List