Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:ovirt:vdsm:1.4.6:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2018-10908 |
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact other users of the host. Published: August 09, 2018; 3:29:00 PM -0400 |
V4.0:(not available) V3.0: 6.3 MEDIUM V2.0: 7.1 HIGH |