PT-2014-2164 · Qemu+2 · Qemu+2
Petr Matousek
·
Published
2011-12-06
·
Updated
2023-02-13
·
CVE-2011-4111
CVSS v2.0
6.8
Medium
| Vector | AV:A/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 0.15.2
QEMU versions 1.x prior to 1.0-rc4
Description
The issue is related to a buffer overflow in the
ccid card vscard handle message function, which can be triggered by a crafted VSC ATR message. This could lead to a denial of service (crash) and potentially allow the execution of arbitrary code.Recommendations
For QEMU versions prior to 0.15.2, update to version 0.15.2 or later.
For QEMU versions 1.x prior to 1.0-rc4, update to version 1.0-rc4 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Qemu
Red Hat