2.1

CVE-2014-3640

The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version7.0
QemuQemu Version2.0.0 Update-
QemuQemu Version2.0.0 Updaterc0
QemuQemu Version2.0.0 Updaterc1
QemuQemu Version2.0.0 Updaterc2
QemuQemu Version2.0.0 Updaterc3
QemuQemu Version2.0.2
QemuQemu Version2.1.0
QemuQemu Version2.1.0 Updaterc0
QemuQemu Version2.1.0 Updaterc1
QemuQemu Version2.1.0 Updaterc2
QemuQemu Version2.1.0 Updaterc3
QemuQemu Version2.1.0 Updaterc5
QemuQemu Version2.1.1
CanonicalUbuntu Linux Version10.04 SwEditionlts
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.156
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.