Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2014-0150
HistoryApr 18, 2014 - 2:55 p.m.

CVE-2014-0150

2014-04-1814:55:25
Debian Security Bug Tracker
security-tracker.debian.org
21

CVSS2

4.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.001

Percentile

36.6%

Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer overflow.

OSVersionArchitecturePackageVersionFilename
Debian12allqemu<Β 1.7.0+dfsg-8qemu_1.7.0+dfsg-8_all.deb
Debian11allqemu<Β 1.7.0+dfsg-8qemu_1.7.0+dfsg-8_all.deb
Debian999allqemu<Β 1.7.0+dfsg-8qemu_1.7.0+dfsg-8_all.deb
Debian13allqemu<Β 1.7.0+dfsg-8qemu_1.7.0+dfsg-8_all.deb

CVSS2

4.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.001

Percentile

36.6%