Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0148

Опубликовано: 29 сент. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

РелизСтатусПримечание
devel

not-affected

2.0.0~rc1+dfsg-0ubuntu3
esm-infra-legacy/trusty

not-affected

2.0.0~rc1+dfsg-0ubuntu3
lucid

DNE

precise

DNE

quantal

DNE

saucy

ignored

end of life
trusty

not-affected

2.0.0~rc1+dfsg-0ubuntu3
trusty/esm

not-affected

2.0.0~rc1+dfsg-0ubuntu3
upstream

released

1.7.2, 2.0

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

not-affected

code not present
precise

not-affected

code not present
quantal

not-affected

code not present
saucy

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 20%
0.00061
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

redhat
около 11 лет назад

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

CVSS3: 5.5
nvd
больше 2 лет назад

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

CVSS3: 5.5
debian
больше 2 лет назад

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to ...

CVSS3: 5.5
github
больше 2 лет назад

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

oracle-oval
около 11 лет назад

ELSA-2014-0420: qemu-kvm security update (MODERATE)

EPSS

Процентиль: 20%
0.00061
Низкий

5.5 Medium

CVSS3