CVE-2019-12247 PUBLISHED

QEMU 3.0.0 has an Integer Overflow because the qga/commands*.c files do not check the length of the argument list or the number of environment variables. NOTE: This has been disputed as not exploitable

EPSS 0.54% · 67.5th percentile

Risk Scores

EPSS Score
0.54%
67.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSqemu0, 1:2.5+dfsg-5ubuntu10.51+esm3, 1:2.5+dfsg-5ubuntu10.51+esm2
Ubuntu:Pro:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.42+esm2, 0, 1:2.10+dfsg-0ubuntu3
Ubuntu:Pro:14.04:LTSqemu2.0.0~rc1+dfsg-0ubuntu3, 2.0.0~rc1+dfsg-0ubuntu2, 2.0.0~rc1+dfsg-0ubuntu1

Timeline

References

Open in Interactive Console →