Vulnerability Summary for the Week of August 21, 2023

 

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source & Patch Info
qemu — qemu The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. 2023-08-22 10 CVE-2022-36648
MISC
c-ares — c-ares Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. 2023-08-22 9.8 CVE-2020-22217
MISC
flac_project — flac Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder. 2023-08-22 This article has been indexed from Bulletins

Read the original article:

Tags: