5
CVE-2020-10761
- EPSS 1.8%
- Veröffentlicht 09.06.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:01
- Erkennungen
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 8.0 SwEdition advanced_virtualization
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.8% | 0.756 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
| RedHat | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://security.gentoo.org/glsa/202011-09
https://usn.ubuntu.com/4467-1/
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10761
https://security.netapp.com/advisory/ntap-20200731-0001/
https://www.openwall.com/lists/oss-security/2020/06/09/1