Lucene search

K
cve[email protected]CVE-2014-2894
HistoryApr 23, 2014 - 3:55 p.m.

CVE-2014-2894

2014-04-2315:55:05
CWE-189
web.nvd.nist.gov
60
cve-2014-2894
qemu
buffer underflow
memory corruption
smart self test
hardware
ide
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

Affected configurations

NVD
Node
qemuqemuRange1.7.1
OR
qemuqemuMatch0.1.0
OR
qemuqemuMatch0.1.1
OR
qemuqemuMatch0.1.2
OR
qemuqemuMatch0.1.3
OR
qemuqemuMatch0.1.4
OR
qemuqemuMatch0.1.5
OR
qemuqemuMatch0.1.6
OR
qemuqemuMatch0.2.0
OR
qemuqemuMatch0.3.0
OR
qemuqemuMatch0.4.0
OR
qemuqemuMatch0.4.1
OR
qemuqemuMatch0.4.2
OR
qemuqemuMatch0.4.3
OR
qemuqemuMatch0.5.0
OR
qemuqemuMatch0.5.1
OR
qemuqemuMatch0.5.2
OR
qemuqemuMatch0.5.3
OR
qemuqemuMatch0.5.4
OR
qemuqemuMatch0.5.5
OR
qemuqemuMatch0.6.0
OR
qemuqemuMatch0.6.1
OR
qemuqemuMatch0.7.0
OR
qemuqemuMatch0.7.1
OR
qemuqemuMatch0.7.2
OR
qemuqemuMatch0.8.0
OR
qemuqemuMatch0.8.1
OR
qemuqemuMatch0.8.2
OR
qemuqemuMatch0.9.0
OR
qemuqemuMatch0.9.1
OR
qemuqemuMatch0.9.1-5
OR
qemuqemuMatch0.10.0
OR
qemuqemuMatch0.10.1
OR
qemuqemuMatch0.10.2
OR
qemuqemuMatch0.10.3
OR
qemuqemuMatch0.10.4
OR
qemuqemuMatch0.10.5
OR
qemuqemuMatch0.10.6
OR
qemuqemuMatch0.11.0
OR
qemuqemuMatch0.11.0rc0
OR
qemuqemuMatch0.11.0rc1
OR
qemuqemuMatch0.11.0rc2
OR
qemuqemuMatch0.11.0-rc0
OR
qemuqemuMatch0.11.0-rc1
OR
qemuqemuMatch0.11.0-rc2
OR
qemuqemuMatch0.11.1
OR
qemuqemuMatch0.12.0
OR
qemuqemuMatch0.12.0rc1
OR
qemuqemuMatch0.12.0rc2
OR
qemuqemuMatch0.12.1
OR
qemuqemuMatch0.12.2
OR
qemuqemuMatch0.12.3
OR
qemuqemuMatch0.12.4
OR
qemuqemuMatch0.12.5
OR
qemuqemuMatch0.13.0
OR
qemuqemuMatch0.13.0rc0
OR
qemuqemuMatch0.13.0rc1
OR
qemuqemuMatch0.14.0
OR
qemuqemuMatch0.14.0rc0
OR
qemuqemuMatch0.14.0rc1
OR
qemuqemuMatch0.14.0rc2
OR
qemuqemuMatch0.14.1
OR
qemuqemuMatch0.15.0rc1
OR
qemuqemuMatch0.15.0rc2
OR
qemuqemuMatch0.15.1
OR
qemuqemuMatch0.15.2
OR
qemuqemuMatch1.0
OR
qemuqemuMatch1.0rc1
OR
qemuqemuMatch1.0rc2
OR
qemuqemuMatch1.0rc3
OR
qemuqemuMatch1.0rc4
OR
qemuqemuMatch1.0.1
OR
qemuqemuMatch1.1
OR
qemuqemuMatch1.1rc1
OR
qemuqemuMatch1.1rc2
OR
qemuqemuMatch1.1rc3
OR
qemuqemuMatch1.1rc4
OR
qemuqemuMatch1.1.1
OR
qemuqemuMatch1.1.2
OR
qemuqemuMatch1.2.0
OR
qemuqemuMatch1.2.0rc0
OR
qemuqemuMatch1.2.0rc1
OR
qemuqemuMatch1.2.0rc2
OR
qemuqemuMatch1.2.0rc3
OR
qemuqemuMatch1.2.1
OR
qemuqemuMatch1.2.2
OR
qemuqemuMatch1.3.0
OR
qemuqemuMatch1.3.0rc0
OR
qemuqemuMatch1.3.0rc1
OR
qemuqemuMatch1.3.0rc2
OR
qemuqemuMatch1.3.1
OR
qemuqemuMatch1.4.0rc0
OR
qemuqemuMatch1.4.0rc1
OR
qemuqemuMatch1.4.1
OR
qemuqemuMatch1.4.2
OR
qemuqemuMatch1.5.0
OR
qemuqemuMatch1.5.0rc1
OR
qemuqemuMatch1.5.0rc2
OR
qemuqemuMatch1.5.0rc3
OR
qemuqemuMatch1.5.1
OR
qemuqemuMatch1.5.2
OR
qemuqemuMatch1.5.3
OR
qemuqemuMatch1.6.0
OR
qemuqemuMatch1.6.0rc1
OR
qemuqemuMatch1.6.0rc2
OR
qemuqemuMatch1.6.0rc3
OR
qemuqemuMatch1.6.1
OR
qemuqemuMatch1.6.2

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%