QEMU CVE-2013-4541 Remote Code Execution Vulnerability
BID:67394
Info
QEMU CVE-2013-4541 Remote Code Execution Vulnerability
| Bugtraq ID: | 67394 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4541 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2014 12:00AM |
| Updated: | Apr 13 2015 09:43PM |
| Credit: | Dr. David Alan Gilbert |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 11 SP3 SuSE Suse Linux Enterprise Desktop 11 SP3 Redhat OpenStack 5.0 Redhat Enterprise Virtualization 3 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 QEMU QEMU 0 Oracle Enterprise Linux 7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 CentOS CentOS 6 |
| Not Vulnerable: | |
References
QEMU CVE-2013-4541 Remote Code Execution Vulnerability
References:
References:
- Bug 1066384 - (CVE-2013-4541) CVE-2013-4541 qemu: usb: insufficient sanity chec (Petr Matousek)
- [PATCH v2] usb: fix up post load checks (Dr. David Alan Gilbert)
- http://seclists.org/oss-sec/2014/q2/303 (Seclists)
- QEMU Homepage (QEMU)
- usb: sanity check setup_index+setup_len in post_load (Michael S. Tsirkin)
- Moderate: qemu-kvm-rhev security update (Red Hat)