PT-2014-5431 · Qemu+5 · Qemu+5

Publicado

2014-09-30

·

Atualizado

2024-06-15

·

CVE-2014-3640

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.1.2
Description The issue allows local users to cause a denial of service by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket. This is due to a problem in the sosendto function in slirp/udp.c.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the sosendto function in slirp/udp.c to minimize the risk of exploitation.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2221
CESA-2015_0349
CVE-2014-3640
DSA-3044-1
DSA-3045-1
MGASA-2014-0426
OPENSUSE-SU-2024:10196-1
RHSA-2015:0349
RHSA-2015:0624
RHSA-2015_0349
SUSE-SU-2015:0357-1
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1154-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1745-1
USN-2409-1

Produtos afetados

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu