Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-5388
HistoryAug 26, 2014 - 12:00 a.m.

CVE-2014-5388

2014-08-2600:00:00
ubuntu.com
ubuntu.com
11

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

26.7%

Off-by-one error in the pci_read function in the ACPI PCI hotplug interface
(hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive
information and have other unspecified impact related to a crafted PCI
device that triggers memory corruption.

Bugs

Notes

Author Note
mdeslaur introduced in 1.7.x by http://git.qemu.org/?p=qemu.git;a=commit;h=db4728e6fec0364b866d3106125974eedc00e091
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchqemu< 2.0.0+dfsg-2ubuntu1.7UNKNOWN
ubuntu14.10noarchqemu< 2.1+dfsg-3ubuntu4UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

26.7%