Lucene search

K
cve[email protected]CVE-2014-9718
HistoryApr 21, 2015 - 4:59 p.m.

CVE-2014-9718

2015-04-2116:59:00
CWE-399
web.nvd.nist.gov
53
qemu
ide interface
security vulnerability
cve-2014-9718
nvd

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%

The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function’s return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.

Affected configurations

NVD
Node
debiandebian_linuxMatch8.0
Node
qemuqemuMatch1.0
OR
qemuqemuMatch1.0rc1
OR
qemuqemuMatch1.0rc2
OR
qemuqemuMatch1.0rc3
OR
qemuqemuMatch1.0rc4
OR
qemuqemuMatch1.0.1
OR
qemuqemuMatch1.1
OR
qemuqemuMatch1.1rc1
OR
qemuqemuMatch1.1rc2
OR
qemuqemuMatch1.1rc3
OR
qemuqemuMatch1.1rc4
OR
qemuqemuMatch1.4.1
OR
qemuqemuMatch1.4.2
OR
qemuqemuMatch1.5.0
OR
qemuqemuMatch1.5.0rc1
OR
qemuqemuMatch1.5.0rc2
OR
qemuqemuMatch1.5.0rc3
OR
qemuqemuMatch1.5.1
OR
qemuqemuMatch1.5.2
OR
qemuqemuMatch1.5.3
OR
qemuqemuMatch1.6.0
OR
qemuqemuMatch1.6.0rc1
OR
qemuqemuMatch1.6.0rc2
OR
qemuqemuMatch1.6.0rc3
OR
qemuqemuMatch1.6.1
OR
qemuqemuMatch1.6.2
OR
qemuqemuMatch1.7.1
OR
qemuqemuMatch2.0.0-
OR
qemuqemuMatch2.0.0rc0
OR
qemuqemuMatch2.0.0rc1
OR
qemuqemuMatch2.0.0rc2
OR
qemuqemuMatch2.0.0rc3
OR
qemuqemuMatch2.0.2
OR
qemuqemuMatch2.1.0
OR
qemuqemuMatch2.1.0rc0
OR
qemuqemuMatch2.1.0rc1
OR
qemuqemuMatch2.1.0rc2
OR
qemuqemuMatch2.1.0rc3
OR
qemuqemuMatch2.1.0rc5
OR
qemuqemuMatch2.1.1
OR
qemuqemuMatch2.1.2
OR
qemuqemuMatch2.1.3

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%