PT-2010-2089 · Qemu+1 · Qemu+1

Published

2010-02-09

·

Updated

2023-02-13

·

CVE-2010-0297

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 0.11.1
Description A buffer overflow issue exists in the usb host handle control function within the USB passthrough handling implementation. This allows guest OS users to potentially cause a denial of service, such as crashing or hanging the guest OS, or possibly execute arbitrary code on the host OS by sending a crafted USB packet.
Recommendations For versions prior to 0.11.1, update to version 0.11.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of USB passthrough functionality until a patch is applied.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2010-0297
RHSA-2010:0088
RHSA-2010:0172
RHSA-2010_0088

Affected Products

Qemu
Red Hat