PT-2014-2164 · Qemu+2 · Qemu+2
CVSS v2.0
6.8
Média
| Vetor | AV:A/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 0.15.2
QEMU versions 1.x prior to 1.0-rc4
Description
The issue is related to a buffer overflow in the
ccid card vscard handle message function, which can be triggered by a crafted VSC ATR message. This could lead to a denial of service (crash) and potentially allow the execution of arbitrary code.Recommendations
For QEMU versions prior to 0.15.2, update to version 0.15.2 or later.
For QEMU versions 1.x prior to 1.0-rc4, update to version 1.0-rc4 or later.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Qemu
Red Hat