QEMU L2 Table Size Validation Integer Overflow Vulnerability
BID:67357
Info
QEMU L2 Table Size Validation Integer Overflow Vulnerability
| Bugtraq ID: | 67357 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0222 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2014 12:00AM |
| Updated: | Jul 05 2016 10:05PM |
| Credit: | Prasad J Pandit |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat Enterprise Virtualization Hypervisor for RHEL 6 0 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 QEMU QEMU 0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
QEMU L2 Table Size Validation Integer Overflow Vulnerability
QEMU is prone to an integer-overflow vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the application. Failed attacks may cause a denial-of-service condition.
QEMU is prone to an integer-overflow vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the application. Failed attacks may cause a denial-of-service condition.
References
QEMU L2 Table Size Validation Integer Overflow Vulnerability
References:
References:
- Bug 1097216 - (CVE-2014-0222) CVE-2014-0222 Qemu: qcow1: validate L2 table size (Red Hat Bugzilla)
- CVE-2014-0222 Qemu: qcow1: Validate L2 table size (SecLists.Org)
- QEMU Homepage (QEMU)
- Security Bulletin: SmartCloud Provisioning - Vulnerabilities in qemu-kvm (CVE-20 (IBM)
- Moderate: qemu-kvm-rhev security update (Red Hat)
- RHSA-2014:1076-1 Moderate: qemu-kvm-rhev security and bug fix update (Red Hat)
- Security Bulletin: Vulnerabilities in qemu-kvm (CVE-2014-0222, CVE-2014-0223) (IBM)