Vulnerabilities > CVE-2020-13765 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 5.6 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
network
high complexity
qemu
canonical
debian
CWE-787

Summary

rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.

Common Weakness Enumeration (CWE)