Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11878
HistoryJan 15, 2019 - 9:09 a.m.

Denial Of Service (DoS)

2019-01-1509:09:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

33.1%

QEMU is vulnerable to denial of service. A heap-based buffer overflow flaw was discovered in the way QEMU’s AMD PC-Net II Ethernet Controller emulation received certain packets in loopback mode. A privileged user (with the CAP_SYS_RAWIO capability) inside a guest could use this flaw to crash the host QEMU process (resulting in denial of service) or, potentially, execute arbitrary code with privileges of the host QEMU process.

References