Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7840

Опубликовано: 12 нояб. 2014
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.

It was found that certain values that were read when loading RAM during migration were not validated. A user able to alter the savevm data (either on the disk or over the wire during migration) could use either of these flaws to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 6qemu-kvmAffected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)qemu-kvm-rhevUnder investigation
Red Hat OpenStack Platform 3qemu-kvm-rhevUnder investigation
Red Hat OpenStack Platform 4qemu-kvm-rhevUnder investigation
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2015:034905.03.2015
RHEV 3.X Hypervisor and Agents for RHEL-7qemu-kvm-rhevFixedRHSA-2015:062405.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1163075qemu: insufficient parameter validation during ram load

EPSS

Процентиль: 85%
0.02455
Низкий

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.

nvd
больше 10 лет назад

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.

debian
больше 10 лет назад

The host_from_stream_offset function in arch_init.c in QEMU, when load ...

github
больше 3 лет назад

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.

suse-cvrf
больше 10 лет назад

Security update for qemu

EPSS

Процентиль: 85%
0.02455
Низкий

3.7 Low

CVSS2