CVE-2020-4467
published 2020-05-14CVE-2020-4467: IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By persuading a…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.77%
84.6th percentile
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 181721.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i2_analysts_notebook | — | — |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.51 | 1:2.5+dfsg-5ubuntu10.51 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.36 | 1:2.11+dfsg-1ubuntu7.36 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.14 | 1:4.2-3ubuntu6.14 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47+esm1 | 2.0.0+dfsg-2ubuntu1.47+esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m7x8-9www-ff8c: IBM i2 Intelligent Analyis Platform 9
ghsa_unreviewed·2022-05-24
CVE-2020-4467 [HIGH] CWE-119 GHSA-m7x8-9www-ff8c: IBM i2 Intelligent Analyis Platform 9
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 181721.
OSV
qemu regression
osv·2021-02-22·CVSS 6.7
CVE-2020-13754 qemu regression
qemu regression
USN-4467-1 fixed vulnerabilities in QEMU. The fix for CVE-2020-13754
introduced a regression in certain environments. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Ren Ding, Hanqing Zhao, Alexander Bulekov, and Anatoly Trosinenko
discovered that the QEMU incorrectly handled certain msi-x mmio operations.
An attacker inside a guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-13754)
OSV
qemu vulnerabilities
osv·2021-02-02·CVSS 5.5
CVE-2020-13253 qemu vulnerabilities
qemu vulnerabilities
USN-4467-1 fixed several vulnerabilities in QEMU. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that the QEMU SD memory card implementation incorrectly
handled certain memory operations. An attacker inside a guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service. (CVE-2020-13253)
Ren Ding and Hanqing Zhao discovered that the QEMU ES1370 audio driver
incorrectly handled certain invalid frame counts. An attacker inside a
guest could possibly use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2020-13361)
Ren Ding and Hanqing Zhao discovered that the QEMU MegaRAID SAS SCSI driver
incorrectly handled certain memory operations. An attacker
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-14
Published