Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1750

Опубликовано: 30 мар. 2011
Источник: redhat
CVSS2: 7.4
EPSS Низкий

Описание

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

Отчет

This issue does not affect versions of kvm package as shipped with Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 6.0qemu-kvmAffected
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2011:053419.05.2011

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=698906virtio-blk: heap buffer overflow caused by unaligned requests

EPSS

Процентиль: 64%
0.0047
Низкий

7.4 High

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

nvd
около 13 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

debian
около 13 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virt ...

github
около 3 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

oracle-oval
около 14 лет назад

ELSA-2011-0534: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 64%
0.0047
Низкий

7.4 High

CVSS2