UBUNTU-CVE-2019-13164
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-13164
UBUNTU-CVE-2019-13164
Summary:
Details: qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
References: https://ubuntu.com/security/CVE-2019-13164, https://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00145.html, https://lists.gnu.org/archive/html/qemu-devel/2019-07/msg00245.html, http://www.openwall.com/lists/oss-security/2019/07/02/2, https://ubuntu.com/security/notices/USN-4191-1, https://ubuntu.com/security/notices/USN-4191-2, https://www.cve.org/CVERecord?id=CVE-2019-13164
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.47?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
