ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
2021-01-26T18:15:51.850
2024-11-21T05:24:00.847
Modified
CVSSv3.1: 3.9 (LOW)
AV:L/AC:M/Au:N/C:P/I:N/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | 5.1.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |