← Back

CVE-2019-12068

nvd nist
Published: Sep 24, 2019Modified: Nov 21, 2024

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Exploitability: 2.0 / Impact: 1.4
Source: NVD

Description

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.

Affected (12)

1 product
Qemu
1 product
Ubuntu Linux
1 product
Leap
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1\ 4.1-1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1\ 2.1+dfsg-12+deb8u6
Running on/withPlatform Versions
Debian
Debian Linux
Version 8.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1\ 2.8+dfsg-6+deb9u8
Running on/withPlatform Versions
Debian
Debian Linux
Version 9.0
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Qemu
Version 1\ 3.1+dfsg-8+deb10u2
Version 1\ 3.1+dfsg-8~deb10u1
Running on/withPlatform Versions
Debian
Debian Linux
Version 10.0
Configuration E
7 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 19.04
Version 19.10
Opensuse
Version 15.0
Version 15.1

References (20)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.