Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12890
HistoryJan 15, 2019 - 9:23 a.m.

Memory Corruption

2019-01-1509:23:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

32.6%

qemu-kvm-rhev is vulnerable to arbitrary code execution attacks. The vulnerability exists as the load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.