Wind River Support Network

HomeDefectsLIN10-5530
Fixed

LIN10-5530 : Security advisory - QEMU - CVE-2019-3812

Created: Mar 8, 2019    Updated: Mar 28, 2019
Resolved Date: Mar 12, 2019
Previous ID: LIN8-10576
Found In Version: 10.17.41.14
Fix Version: 10.17.41.15
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

CVE-2019-3812 -A vulnerability in QEMU could allow a local attacker to access sensitive information on a targeted system.

The vulnerability is due to an out-of-bounds read condition in the i2c_ddc() function, as defined in the hw/i2c/i2c-ddc.c source code file of the affected software. An attacker could exploit this vulnerability by executing malicious i2c commands on the targeted system. A successful exploit could trigger an out-of-bounds read condition, allowing the attacker to access sensitive information on a targeted system.

CVEs


Live chat
Online