CVE-2020-29443 log

Source
Severity Low
Remote No
Type Directory traversal
Description
An out-of-bounds read access issue was found in the ATAPI Emulator of QEMU. It occurs while processing ATAPI read command if logical block address(LBA) is set an invalid value. A guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
Group Package Affected Fixed Severity Status Ticket
AVG-1308 qemu 5.2.0-3 Medium Vulnerable
References
https://www.openwall.com/lists/oss-security/2021/01/18/2
https://bugzilla.redhat.com/show_bug.cgi?id=1917446
https://git.qemu.org/?p=qemu.git;a=commitdiff;h=b8d7f1bc59276fec85e4d09f1567613a3e14d31e