Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0928
HistoryMar 03, 2008 - 12:00 a.m.

CVE-2008-0928

2008-03-0300:00:00
ubuntu.com
ubuntu.com
16

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS

0.001

Percentile

28.7%

Qemu 0.9.1 and earlier does not perform range checks for block device read
or write requests, which allows guest host users with root privileges to
access arbitrary memory and escape the virtual machine.

Bugs

Notes

Author Note
kees note that the original patch corrupts growable devices, see RH bug
jdstrand there is now an updated patch in the RH bug 434978 Debian claims that patches break existing images
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchkvm< 1:62+dfsg-0ubuntu3UNKNOWN

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS

0.001

Percentile

28.7%