Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1750

Опубликовано: 30 мар. 2011
Источник: redhat
CVSS2: 7.4
EPSS Низкий

Описание

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

Отчет

This issue does not affect versions of kvm package as shipped with Red Hat Enterprise Linux 5.

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=698906virtio-blk: heap buffer overflow caused by unaligned requests

EPSS

Процентиль: 50%
0.00718
Низкий

7.4 High

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

nvd
около 14 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

debian
около 14 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virt ...

github
около 4 лет назад

Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

oracle-oval
около 15 лет назад

ELSA-2011-0534: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 50%
0.00718
Низкий

7.4 High

CVSS2