Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11674
HistoryJan 15, 2019 - 9:05 a.m.

Denial Of Service (DoS)

2019-01-1509:05:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

41.0%

qemu-kvm is vulnerable to denial of service (DoS) attacks. The vulnerability exists as the Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.Though the VENOM vulnerability is also agnostic of the guest operating system, an attacker (or an attacker’s malware) would need to have administrative or root privileges in the guest operating system in order to exploit VENOM.

References