Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4537

Опубликовано: 03 дек. 2013
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

Отчет

Not vulnerable. This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5. This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 6

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1066394qemu: ssi-sd: buffer overrun on invalid state load

EPSS

Процентиль: 85%
0.02927
Низкий

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

nvd
почти 12 лет назад

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

debian
почти 12 лет назад

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 al ...

github
около 4 лет назад

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

suse-cvrf
больше 10 лет назад

Security update for xen

EPSS

Процентиль: 85%
0.02927
Низкий

3.7 Low

CVSS2