PT-2014-5431 · Qemu+5 · Qemu+5

Published

2014-09-30

·

Updated

2024-06-15

·

CVE-2014-3640

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.1.2
Description The issue allows local users to cause a denial of service by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket. This is due to a problem in the sosendto function in slirp/udp.c.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the sosendto function in slirp/udp.c to minimize the risk of exploitation.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2221
CESA-2015_0349
CVE-2014-3640
DSA-3044-1
DSA-3045-1
MGASA-2014-0426
OPENSUSE-SU-2024:10196-1
RHSA-2015:0349
RHSA-2015:0624
RHSA-2015_0349
SUSE-SU-2015:0357-1
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1154-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1745-1
USN-2409-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu