CVE-2019-15034

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
10/03/2020
Last modified:
28/05/2020

Description

hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qemu:qemu:4.0.0:*:*:*:*:*:*:*