Описание
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qemu | fixed | 1:2.5+dfsg-1 | package | |
| qemu | no-dsa | wheezy | package | |
| qemu | end-of-life | squeeze | package | |
| qemu-kvm | removed | package | ||
| qemu-kvm | end-of-life | squeeze | package | |
| qemu-kvm | no-dsa | wheezy | package |
Примечания
Upstream commit: http://git.qemu.org/?p=qemu.git;a=commitdiff;h=d9a3b33d2c9f996537b7f1d0246dee2d0120cefb (v2.5.0-rc1)
https://bugzilla.redhat.com/show_bug.cgi?id=1283722
https://www.openwall.com/lists/oss-security/2015/12/24/1
Vulnerable code introduced after 0.14.50: http://git.qemu.org/?p=qemu.git;a=commit;h=23910d3f669d46073b403876e30a7314599633af
EPSS
Связанные уязвимости
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
EPSS