Lucene search

K
cve[email protected]CVE-2013-4377
HistoryOct 11, 2013 - 10:55 p.m.

CVE-2013-4377

2013-10-1122:55:40
CWE-399
web.nvd.nist.gov
46
cve-2013-4377
use-after-free
qemu
virtualization
vulnerability
local users
denial of service
nvd

2.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:N/I:N/A:P

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by “hot-unplugging” a virtio device.

Affected configurations

NVD
Node
qemuqemuMatch1.4.0
OR
qemuqemuMatch1.4.1
OR
qemuqemuMatch1.4.2
OR
qemuqemuMatch1.5.0
OR
qemuqemuMatch1.5.0rc1
OR
qemuqemuMatch1.5.0rc2
OR
qemuqemuMatch1.5.0rc3
OR
qemuqemuMatch1.5.1
OR
qemuqemuMatch1.5.2
OR
qemuqemuMatch1.5.3
OR
qemuqemuMatch1.6.0
OR
qemuqemuMatch1.6.0rc1
OR
qemuqemuMatch1.6.0rc2
OR
qemuqemuMatch1.6.0rc3

2.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:N/I:N/A:P

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%