7.2
CVE-2013-4344
- EPSS 0.43%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Virtualization Version 3.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.345 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
http://article.gmane.org/gmane.comp.emulators.qemu/237191
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.html
http://osvdb.org/98028
http://rhn.redhat.com/errata/RHSA-2013-1553.html
http://rhn.redhat.com/errata/RHSA-2013-1754.html
http://www.openwall.com/lists/oss-security/2013/10/02/2
http://www.securityfocus.com/bid/62773
http://www.ubuntu.com/usn/USN-2092-1