Lucene search

K
cve[email protected]CVE-2014-3640
HistoryNov 07, 2014 - 7:55 p.m.

CVE-2014-3640

2014-11-0719:55:02
CWE-476
web.nvd.nist.gov
49
cve-2014-3640
qemu
sosendto function
slirp
udp.c
null pointer dereference
denial of service

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.

Affected configurations

NVD
Node
debiandebian_linuxMatch7.0
Node
qemuqemuMatch2.0.0-
OR
qemuqemuMatch2.0.0rc0
OR
qemuqemuMatch2.0.0rc1
OR
qemuqemuMatch2.0.0rc2
OR
qemuqemuMatch2.0.0rc3
OR
qemuqemuMatch2.0.2
OR
qemuqemuMatch2.1.0
OR
qemuqemuMatch2.1.0rc0
OR
qemuqemuMatch2.1.0rc1
OR
qemuqemuMatch2.1.0rc2
OR
qemuqemuMatch2.1.0rc3
OR
qemuqemuMatch2.1.0rc5
OR
qemuqemuMatch2.1.1
Node
redhatenterprise_linux_desktopMatch7.0
OR
redhatenterprise_linux_hpc_nodeMatch7.0
OR
redhatenterprise_linux_serverMatch7.0
OR
redhatenterprise_linux_workstationMatch7.0
Node
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%