7.5

CVE-2013-4151

The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version 1.0
Qemu ≫ Qemu Version 1.0 Update rc1
Qemu ≫ Qemu Version 1.0 Update rc2
Qemu ≫ Qemu Version 1.0 Update rc3
Qemu ≫ Qemu Version 1.0 Update rc4
Qemu ≫ Qemu Version 1.0.1
Qemu ≫ Qemu Version 1.1
Qemu ≫ Qemu Version 1.1 Update rc1
Qemu ≫ Qemu Version 1.1 Update rc2
Qemu ≫ Qemu Version 1.1 Update rc3
Qemu ≫ Qemu Version 1.1 Update rc4
Qemu ≫ Qemu Version 1.4.1
Qemu ≫ Qemu Version 1.4.2
Qemu ≫ Qemu Version 1.5.0
Qemu ≫ Qemu Version 1.5.0 Update rc1
Qemu ≫ Qemu Version 1.5.0 Update rc2
Qemu ≫ Qemu Version 1.5.0 Update rc3
Qemu ≫ Qemu Version 1.5.1
Qemu ≫ Qemu Version 1.5.2
Qemu ≫ Qemu Version 1.5.3
Qemu ≫ Qemu Version 1.6.0
Qemu ≫ Qemu Version 1.6.0 Update rc1
Qemu ≫ Qemu Version 1.6.0 Update rc2
Qemu ≫ Qemu Version 1.6.0 Update rc3
Qemu ≫ Qemu Version 1.6.1
Qemu ≫ Qemu Version 1.6.2
Qemu ≫ Qemu Version 1.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.13% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://rhn.redhat.com/errata/RHSA-2014-0743.html
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2014-0744.html
Patch
Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.html
http://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.html
Patch
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=cc45995294b92d95319b4782750a3580cabdbc0c