PT-2013-1874 · Qemu+3 · Qemu+3

Jan Lieskovsky

·

Published

2013-02-13

·

Updated

2024-06-15

·

CVE-2012-6075

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions 1.3.0-rc2 and other versions
Description The issue is related to a buffer overflow in the e1000 receive function in the e1000 device driver. This occurs when the SBP and LPE flags are disabled, allowing remote attackers to cause a denial of service, potentially leading to a guest OS crash, and possibly execute arbitrary guest code via a large packet.
Recommendations For QEMU version 1.3.0-rc2, consider disabling the e1000 device driver until a patch is available. For other affected versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0609
CVE-2012-6075
DSA-2607-1
DSA-2608-1
DSA-2619-1
OPENSUSE-SU-2024:10196-1
RHSA-2013:0599
RHSA-2013:0608
RHSA-2013:0609
RHSA-2013:0610
RHSA-2013:0636
RHSA-2013:0639
RHSA-2013_0599
RHSA-2013_0608
RHSA-2013_0609
SUSE-SU-2015:0944-1

Affected Products

Centos
Qemu
Red Hat
Suse