Lucene search

K
ubuntuUbuntuUSN-2182-1
HistoryApr 28, 2014 - 12:00 a.m.

QEMU vulnerabilities

2014-04-2800:00:00
ubuntu.com
47

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

42.0%

Releases

  • Ubuntu 14.04 ESM
  • Ubuntu 13.10
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • qemu - Machine emulator and virtualizer
  • qemu-kvm - Machine emulator and virtualizer

Details

Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3
devices. A local guest could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code on the host. This issue only
applied to Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-4544)

Michael S. Tsirkin discovered that QEMU incorrectly handled virtio-net
MAC addresses. A local guest could possibly use this issue to cause a
denial of service, or possibly execute arbitrary code on the host.
(CVE-2014-0150)

Benoรฎt Canet discovered that QEMU incorrectly handled SMART self-tests. A
local guest could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code on the host. (CVE-2014-2894)

OSVersionArchitecturePackageVersionFilename
Ubuntu14.04noarchqemu-system<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-guest-agent<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-kvm<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-arm<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-common<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-mips<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-misc<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-ppc<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchqemu-system-sparc<ย 2.0.0~rc1+dfsg-0ubuntu3.1UNKNOWN
Rows per page:
1-10 of 431

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

42.0%