Vulnerability Description
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | <= 3.1.0 |
| Opensuse | Leap | 15.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.htmlMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/02/21/1Mailing ListPatch
- http://www.securityfocus.com/bid/107115Third Party AdvisoryVDB Entry
- https://lists.gnu.org/archive/html/qemu-devel/2019-02/msg04821.htmlExploitMailing ListPatch
- https://security.netapp.com/advisory/ntap-20190411-0006/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.htmlMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/02/21/1Mailing ListPatch
- http://www.securityfocus.com/bid/107115Third Party AdvisoryVDB Entry
- https://lists.gnu.org/archive/html/qemu-devel/2019-02/msg04821.htmlExploitMailing ListPatch
- https://security.netapp.com/advisory/ntap-20190411-0006/Third Party Advisory
FAQ
What is CVE-2019-8934?
CVE-2019-8934 is a vulnerability with a CVSS score of 3.3 (LOW). hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
How severe is CVE-2019-8934?
CVE-2019-8934 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8934?
Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Opensuse Leap.