PT-2014-8410 · Qemu+5 · Qemu+5

Published

2014-12-08

·

Updated

2024-06-15

·

CVE-2014-8106

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.2.0
Description The issue is related to a heap-based buffer overflow in the Cirrus VGA emulator. This allows local guest users to execute arbitrary code via vectors related to blit regions. The problem exists due to an incomplete fix for a previous issue.
Recommendations For QEMU versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cirrus VGA emulator until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2465
CESA-2015_0349
CESA-2015_0867
CVE-2014-8106
DSA-3087-1
DSA-3088-1
MGASA-2014-0525
OPENSUSE-SU-2024:11287-1
RHSA-2015:0349
RHSA-2015:0624
RHSA-2015:0643
RHSA-2015:0795
RHSA-2015:0867
RHSA-2015:0868
RHSA-2015:0891
RHSA-2015_0349
RHSA-2015_0867
SUSE-SU-2015:0349-1
SUSE-SU-2015:0357-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0718-1
SUSE-SU-2017_0582-1
SUSE-SU-2017_0647-1
SUSE-SU-2017_0718-1
USN-2439-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu