Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2008-0928
HistoryMar 03, 2008 - 10:44 p.m.

CVE-2008-0928

2008-03-0322:44:00
Debian Security Bug Tracker
security-tracker.debian.org
25

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS

0.001

Percentile

28.7%

Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.

OSVersionArchitecturePackageVersionFilename
Debian12allqemu< 0.9.1+svn20081207-1qemu_0.9.1+svn20081207-1_all.deb
Debian11allqemu< 0.9.1+svn20081207-1qemu_0.9.1+svn20081207-1_all.deb
Debian999allqemu< 0.9.1+svn20081207-1qemu_0.9.1+svn20081207-1_all.deb
Debian13allqemu< 0.9.1+svn20081207-1qemu_0.9.1+svn20081207-1_all.deb

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS

0.001

Percentile

28.7%