PT-2014-4951 · Qemu+5 · Qemu+5
Benoît Canet
·
Publicado
2014-04-22
·
Atualizado
2023-02-13
·
CVE-2014-2894
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 2.0
Description
The issue is caused by an off-by-one error in the cmd smart function in the smart self test in hw/ide/core.c. This error can be triggered by a SMART EXECUTE OFFLINE command, leading to a buffer underflow and memory corruption.
Recommendations
For versions prior to 2.0, update to version 2.0 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu