Vulnerability Description
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
CVSS Score
3.3
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | < 5.0.0 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=7a4ede0047a8613b0e3b72c9d351038f
- https://usn.ubuntu.com/4467-1/PatchThird Party Advisory
- https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=7a4ede0047a8613b0e3b72c9d351038f
- https://usn.ubuntu.com/4467-1/PatchThird Party Advisory
FAQ
What is CVE-2020-14415?
CVE-2020-14415 is a vulnerability with a CVSS score of 3.3 (LOW). oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
How severe is CVE-2020-14415?
CVE-2020-14415 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14415?
Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Canonical Ubuntu Linux.