CVE-2020-13361: Low severity Qemu Qemu vulnerability
In QEMU 5.0.0 and earlier, es1370transferaudio in hw/audio/es1370.c ...
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-13361?
CVE-2020-13361 is a vulnerability in QEMU 5.0.0 and earlier that allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
How severe is CVE-2020-13361?
CVE-2020-13361 has a severity value of 3.9, indicating a high severity.
Which software versions are affected by CVE-2020-13361?
QEMU versions 5.0.0 and earlier, as well as specific versions of Ubuntu, Debian, openSUSE Leap, and Canonical Ubuntu Linux, are affected by CVE-2020-13361.
How can I fix CVE-2020-13361?
To fix CVE-2020-13361, it is recommended to update to the patched versions of QEMU, if available, provided by the respective vendors.
Where can I find more information about CVE-2020-13361?
You can find more information about CVE-2020-13361 in the references provided: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html), [http://www.openwall.com/lists/oss-security/2020/05/28/1](http://www.openwall.com/lists/oss-security/2020/05/28/1), [https://lists.debian.org/debian-lts-announce/2020/06/msg00032.html](https://lists.debian.org/debian-lts-announce/2020/06/msg00032.html)