tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
The product uses or accesses a resource that has not been initialized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | 3.0.0 (including) | 3.0.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | qemu-kvm-2:0.12.1.2-2.506.el6_10.4 | * |
Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-10:1.5.3-167.el7 | * |
Red Hat Enterprise Linux 8 | RedHat | virt-devel:rhel-8010020190916153839.cdc1202b | * |
Red Hat Enterprise Linux 8 | RedHat | virt:rhel-8010020190916153839.cdc1202b | * |
Red Hat OpenStack Platform 10.0 (Newton) | RedHat | qemu-kvm-rhev-10:2.12.0-33.el7 | * |
Red Hat OpenStack Platform 13.0 (Queens) | RedHat | qemu-kvm-rhev-10:2.12.0-33.el7 | * |
Red Hat OpenStack Platform 14.0 (Rocky) | RedHat | qemu-kvm-rhev-10:2.12.0-33.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | qemu-kvm-rhev-10:2.12.0-33.el7 | * |
Red Hat Virtualization Engine 4.3 | RedHat | qemu-kvm-rhev-10:2.12.0-33.el7 | * |
Qemu | Ubuntu | bionic | * |
Qemu | Ubuntu | cosmic | * |
Qemu | Ubuntu | devel | * |
Qemu | Ubuntu | disco | * |
Qemu | Ubuntu | eoan | * |
Qemu | Ubuntu | focal | * |
Qemu | Ubuntu | groovy | * |
Qemu | Ubuntu | hirsute | * |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | xenial | * |
Qemu-kvm | Ubuntu | precise/esm | * |