QEMU Translation Block Local Denial of Service Vulnerability
BID:26666
Info
QEMU Translation Block Local Denial of Service Vulnerability
| Bugtraq ID: | 26666 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6227 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 30 2007 12:00AM |
| Updated: | Aug 08 2008 03:06PM |
| Credit: | TeLeMan is credited with the discovery of this issue. |
| Vulnerable: |
QEMU QEMU 0.9 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 |
| Not Vulnerable: | |
Discussion
QEMU Translation Block Local Denial of Service Vulnerability
QEMU is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks when handling user-supplied input.
Attackers can exploit this issue to cause denial-of-service conditions. Given the nature of the issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
QEMU 0.9.0 is vulnerable; other versions may also be affected.
QEMU is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks when handling user-supplied input.
Attackers can exploit this issue to cause denial-of-service conditions. Given the nature of the issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
QEMU 0.9.0 is vulnerable; other versions may also be affected.
Exploit / POC
QEMU Translation Block Local Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
QEMU Translation Block Local Denial of Service Vulnerability
Solution:
The vendor has released a fix and an advisory. Please see the references for more information.
Solution:
The vendor has released a fix and an advisory. Please see the references for more information.
References
QEMU Translation Block Local Denial of Service Vulnerability
References:
References:
- Vendor Homepage (QEMU)
- QEMU code_gen_buffer overflow POC (TeLeMan
)