QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
BID:67392
Info
QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 67392 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3461 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2014 12:00AM |
| Updated: | Apr 13 2015 10:24PM |
| Credit: | Dr. David Alan Gilbert |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat OpenStack 5.0 Redhat Enterprise Virtualization 3 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 QEMU QEMU 0 Oracle Enterprise Linux 7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
QEMU is prone to a heap-based buffer-overflow vulnerability.
Successful exploits may allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
QEMU is prone to a heap-based buffer-overflow vulnerability.
Successful exploits may allow attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Exploit / POC
QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64usbredirhost-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirhost1-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirparser-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirparser1-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva qemu-1.6.2-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva qemu-img-1.6.2-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva usbredir-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva usbredir-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
QEMU 'hw/usb/bus.c' Heap Based Buffer Overflow Vulnerability
References:
References:
- Bug 1283722 - Qemu: acpi: heap based buffer overrun during VM migration (Red Hat Bugzilla)
- [PATCH v2] usb: fix up post load checks (Dr. David Alan Gilbert)
- acpi: fix buffer overrun on migration (Michael S. Tsirkin)
- QEMU Homepage (QEMU)
- Moderate: qemu-kvm-rhev security update (Red Hat)