Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3471

Опубликовано: 12 янв. 2018
Источник: debian

Описание

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed2.1+dfsg-1package
qemunot-affectedwheezypackage
qemu-kvmnot-affectedwheezypackage
qemunot-affectedsqueezepackage
qemu-kvmremovedpackage
qemu-kvmnot-affectedsqueezepackage

Примечания

  • https://lists.gnu.org/archive/html/qemu-devel/2014-06/msg05283.html

  • Upstream fix: http://git.qemu.org/?p=qemu.git;a=commit;h=554f802da3f8b09b16b9a84ad5847b2eb0e9ad2b (v2.1.0-rc0)

  • PCIe support introduced in v1.3: http://wiki.qemu.org/ChangeLog/1.3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

redhat
больше 11 лет назад

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

CVSS3: 5.5
nvd
около 8 лет назад

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

CVSS3: 5.5
github
больше 3 лет назад

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.