QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
BID:47927
Info
QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
| Bugtraq ID: | 47927 |
| Class: | Design Error |
| CVE: |
CVE-2011-1751 |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2011 12:00AM |
| Updated: | Oct 18 2012 10:50PM |
| Credit: | Nelson Elhage |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Qumranet KVM 79 Qumranet KVM 36 Qumranet KVM 0 QEMU QEMU 0.10.6 QEMU QEMU 0.9.1 QEMU QEMU 0.9 QEMU QEMU 0.8.2 QEMU QEMU 0.6.1 QEMU QEMU 0.10 QEMU QEMU 0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
QEMU is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code on the host operating system. Failed exploit attempts will result in a denial-of-service condition.
QEMU is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code on the host operating system. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
QEMU PIIX4 Hotplug Use After Free Remote Code Execution Vulnerability
References:
References: