PT-2014-2826 · Qemu+5 · Qemu+5

Anthony Liguori

+2

·

Publicado

2014-02-20

·

Atualizado

2024-06-15

·

CVE-2013-4541

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 1.7.2
Description The issue is related to the usb device post load function in hw/usb/bus.c, which might allow remote attackers to execute arbitrary code via a crafted savevm image. This is due to a negative setup len or setup index value.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to savevm images to minimize the risk of exploitation.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1526
CESA-2014_0743
CESA-2014_0927
CVE-2013-4541
MGASA-2014-0426
OPENSUSE-SU-2024:10233-1
RHSA-2014:0674
RHSA-2014:0743
RHSA-2014:0744
RHSA-2014:0888
RHSA-2014:0927
RHSA-2014:1268
RHSA-2014_0743
RHSA-2014_0927
SUSE-SU-2015:0870-1
SUSE-SU-2015:0889-1
SUSE-SU-2015:1152-1
USN-2342-1

Produtos afetados

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu