Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4344

Опубликовано: 02 окт. 2013
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

Отчет

This issue does not affect the kvm and xen packages as shipped with Red Hat Enterprise Linux 5. This issue does affect the qemu-kvm package as shipped with Red Hat Enterprise Linux 6. Future qemu-kvm updates in Red Hat Enterprise Linux 6 may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2013:155320.11.2013
RHEV 3.X Hypervisor and Agents for RHEL-6qemu-kvm-rhevFixedRHSA-2013:175421.11.2013
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2013:152721.11.2013

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1007330qemu: buffer overflow in scsi_target_emulate_report_luns

EPSS

Процентиль: 21%
0.00068
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

nvd
почти 12 лет назад

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

debian
почти 12 лет назад

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, wh ...

github
больше 3 лет назад

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

oracle-oval
почти 12 лет назад

ELSA-2013-1553: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 21%
0.00068
Низкий

4 Medium

CVSS2