PT-2014-3522 · Qemu+5 · Qemu+5

Anthony Liguori

+2

·

Publicado

2014-04-18

·

Atualizado

2024-06-15

·

CVE-2014-0182

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 1.7.2
Description A heap-based buffer overflow issue exists in the virtio load function, located in hw/virtio/virtio.c, which could potentially allow remote attackers to execute arbitrary code. This is achievable by providing a crafted config length in a savevm image.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1526
CESA-2014_0743
CESA-2014_0927
CVE-2014-0182
MGASA-2014-0426
OPENSUSE-SU-2024:10233-1
RHSA-2014:0674
RHSA-2014:0743
RHSA-2014:0744
RHSA-2014:0888
RHSA-2014:0927
RHSA-2014:1268
RHSA-2014_0743
RHSA-2014_0927
USN-2342-1

Produtos afetados

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu