CVE-2019-5604 - CERT CVE
ID CVE-2019-5604
Sažetak In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, the emulated XHCI device included with the bhyve hypervisor did not properly validate data provided by the guest, allowing an out-of-bounds read. This provides a malicious guest the possibility to crash the system or access system memory.
Reference
CVSS
Base: 8.5
Impact: 9.2
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE COMPLETE
CVSS vektor AV:N/AC:L/Au:S/C:C/I:N/A:C
Zadnje važnije ažuriranje 01-03-2023 - 16:20
Objavljeno 26-07-2019 - 01:15