CVE-2019-15034
published 2020-03-10CVE-2019-15034: hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended…
PriorityP422medium5.8CVSS 3.1
AVLACHPRLUINSUCLILAH
EPSS
0.37%
29.8th percentile
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:4.1-1 (bookworm) | qemu 1:4.1-1 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:4.1-1 | 1:4.1-1 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.44 | 1:2.5+dfsg-5ubuntu10.44 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.26 | 1:2.11+dfsg-1ubuntu7.26 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.1 | 1:4.2-3ubuntu6.1 |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This is
Red Hat
qemu: hw/display/bochs-display.c does not ensure a sufficient PCI config space allocation leading to a buffer overflow involving the PCIe extended config space
vendor_redhat·2019-08-12·CVSS 5.8
CVE-2019-15034 [MEDIUM] CWE-120 qemu: hw/display/bochs-display.c does not ensure a sufficient PCI config space allocation leading to a buffer overflow involving the PCIe extended config space
qemu: hw/display/bochs-display.c does not ensure a sufficient PCI config space allocation leading to a buffer overflow involving the PCIe extended config space
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
A buffer overflow flaw was found in the way the Bochs display driver of QEMU handled the PCIe extended configuration space when the device is connected to a PCIe bus. Accessing the PCIe extended config space could overflow the conventional PCI config space buffer due to limited memory allocation. As the PCIe config space is guest writeable, this flaw allows a local attacker to gain access and potentially execute arbitrary code on the host with the privileges of th
Debian
CVE-2019-15034: qemu - hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config...
vendor_debian·2019·CVSS 5.8
CVE-2019-15034 [MEDIUM] CVE-2019-15034: qemu - hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config...
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
Scope: local
bookworm: resolved (fixed in 1:4.1-1)
bullseye: resolved (fixed in 1:4.1-1)
forky: resolved (fixed in 1:4.1-1)
sid: resolved (fixed in 1:4.1-1)
trixie: resolved (fixed in 1:4.1-1)
GHSA
GHSA-7pcg-64mr-xg9c: hw/display/bochs-display
ghsa_unreviewed·2022-05-24
CVE-2019-15034 [MEDIUM] CWE-120 GHSA-7pcg-64mr-xg9c: hw/display/bochs-display
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
OSV
qemu vulnerabilities
osv·2020-05-21·CVSS 5.8
CVE-2019-15034 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU incorrectly handled bochs-display devices. A
local attacker in a guest could use this to cause a denial of service or
possibly execute arbitrary code in the host. This issue only affected
Ubuntu 19.10. (CVE-2019-15034)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. A remote attacker could possibly use this issue to cause QEMU
to consume resources, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10.
(CVE-2019-20382)
It was discovered that QEMU incorrectly generated QEMU Pointer
Authentication signatures on ARM. A local attacker could possibly use this
issue to bypass PAuth. This issue only affected Ubuntu 19.10.
(CVE-2020-10702)
Ziming Zhan
OSV
CVE-2019-15034: hw/display/bochs-display
osv·2020-03-10·CVSS 5.8
CVE-2019-15034 [MEDIUM] CVE-2019-15034: hw/display/bochs-display
hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01959.htmlhttps://usn.ubuntu.com/4372-1/https://www.debian.org/security/2020/dsa-4665http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01959.htmlhttps://usn.ubuntu.com/4372-1/https://www.debian.org/security/2020/dsa-4665
2020-03-10
Published