PT-2013-1874 · Qemu+3 · Qemu+3

Jan Lieskovsky

·

Publicado

2013-02-13

·

Atualizado

2024-06-15

·

CVE-2012-6075

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions 1.3.0-rc2 and other versions
Description The issue is related to a buffer overflow in the e1000 receive function in the e1000 device driver. This occurs when the SBP and LPE flags are disabled, allowing remote attackers to cause a denial of service, potentially leading to a guest OS crash, and possibly execute arbitrary guest code via a large packet.
Recommendations For QEMU version 1.3.0-rc2, consider disabling the e1000 device driver until a patch is available. For other affected versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0609
CVE-2012-6075
DSA-2607-1
DSA-2608-1
DSA-2619-1
OPENSUSE-SU-2024:10196-1
RHSA-2013:0599
RHSA-2013:0608
RHSA-2013:0609
RHSA-2013:0610
RHSA-2013:0636
RHSA-2013:0639
RHSA-2013_0599
RHSA-2013_0608
RHSA-2013_0609
SUSE-SU-2015:0944-1

Produtos afetados

Centos
Qemu
Red Hat
Suse