9.3
CVE-2012-6075
- EPSS 4.9%
- Veröffentlicht 13.02.2013 01:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 16
Fedoraproject ≫ Fedora Version 17
Fedoraproject ≫ Fedora Version 18
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 5.9
Redhat ≫ Enterprise Linux Eus Version 6.4
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 5.9
Redhat ≫ Enterprise Linux Server Aus Version 6.4
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Virtualization Version 3.0
Debian ≫ Debian Linux Version 6.0
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.9% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html
http://secunia.com/advisories/55082
http://security.gentoo.org/glsa/glsa-201309-24.xml
http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=b0d9ffcd0251161c7c92f94804dcf599dfa3edeb
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/097541.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/097575.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/097705.html
http://lists.nongnu.org/archive/html/qemu-devel/2012-12/msg00533.html
http://rhn.redhat.com/errata/RHSA-2013-0599.html
http://rhn.redhat.com/errata/RHSA-2013-0608.html
http://rhn.redhat.com/errata/RHSA-2013-0609.html
http://rhn.redhat.com/errata/RHSA-2013-0610.html
http://rhn.redhat.com/errata/RHSA-2013-0639.html
http://www.debian.org/security/2013/dsa-2607
http://www.debian.org/security/2013/dsa-2608
http://www.debian.org/security/2013/dsa-2619
http://www.openwall.com/lists/oss-security/2012/12/30/1
http://www.securityfocus.com/bid/57420
http://www.ubuntu.com/usn/USN-1692-1
https://bugzilla.redhat.com/show_bug.cgi?id=889301