Oval Definition:oval:com.ubuntu.bionic:def:2018126170000000
Revision Date:2018-06-21Version:1
Title:CVE-2018-12617 on Ubuntu 18.04 LTS (bionic) - medium.
Description:qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-12617
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND qemu package in bionic was vulnerable but has been fixed (note: '1:2.11+dfsg-1ubuntu7.8').
  • BACK