QEMU Multiple Memory Corruption Vulnerabilities
BID:67483
Info
QEMU Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 67483 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-4148 CVE-2013-4149 CVE-2013-4150 CVE-2013-4151 CVE-2013-4526 CVE-2013-4527 CVE-2013-4529 CVE-2013-4530 CVE-2013-4531 CVE-2013-4533 CVE-2013-4534 CVE-2013-4535 CVE-2013-4536 CVE-2013-4537 CVE-2013-4538 CVE-2013-4539 CVE-2013-4540 CVE-2013-4542 CVE-2013-6399 |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2014 12:00AM |
| Updated: | Jul 05 2016 10:05PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 QEMU QEMU 0 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
QEMU Multiple Memory Corruption Vulnerabilities
QEMU is prone to multiple memory-corruption vulnerabilities.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts might lead to denial-of-service conditions.
QEMU is prone to multiple memory-corruption vulnerabilities.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts might lead to denial-of-service conditions.
Exploit / POC
QEMU Multiple Memory Corruption Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
QEMU Multiple Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64usbredirhost-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirhost1-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirparser-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64usbredirparser1-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva qemu-1.6.2-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva qemu-img-1.6.2-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva usbredir-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva usbredir-devel-0.7-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
QEMU Multiple Memory Corruption Vulnerabilities
References:
References:
- Bug #1066334 - CVE-2013-4148 qemu: virtio-net: buffer overflow on invalid state (Red Hat Bugzilla)
- Bug #1066337 - CVE-2013-4149 qemu: virtio-net: out-of-bounds buffer write on lo (Red Hat Bugzilla)
- Bug #1066340 - CVE-2013-4150 qemu: virtio-net: out-of-bounds buffer write on in (Red Hat Bugzilla)
- Bug #1066342 - CVE-2013-4151 qemu: virtio: out-of-bounds buffer write on invali (Red Hat Bugzilla)
- Bug #1066345 - CVE-2013-4526 qemu: ahci: fix buffer overrun on invalid state lo (Red Hat Bugzilla)
- Bug #1066347 - CVE-2013-4527 qemu: hpet: buffer overrun on invalid state load (Red Hat Bugzilla)
- Bug #1066353 - CVE-2013-4529 qemu: hw/pci/pcie_aer.c: buffer overrun on invalid (Red Hat Bugzilla)
- Bug #1066354 - CVE-2013-4530 qemu: pl022: fix buffer overun on invalid state lo (Red Hat Bugzilla)
- Bug #1066357 - CVE-2013-4531 qemu: target-arm/machine.c: fix buffer overflow on (Red Hat Bugzilla)
- Bug #1066361 - CVE-2013-6399 qemu: virtio: buffer overrun on incoming migration (Red Hat Bugzilla)
- Bug #1066382 - CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state (Red Hat Bugzilla)
- Bug #1066386 - CVE-2013-4540 qemu: zaurus: buffer overrun on invalid state load (Red Hat Bugzilla)
- Bug #1066387 - CVE-2013-4539 qemu: tsc210x: buffer overrun on invalid state loa (Red Hat Bugzilla)
- Bug #1066393 - CVE-2013-4538 qemu: ssd0323: fix buffer overun on invalid state (Red Hat Bugzilla)
- Bug #1066394 - CVE-2013-4537 qemu: ssi-sd: buffer overrun on invalid state load (Red Hat Bugzilla)
- Bug #1066401 - CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validatio (Red Hat Bugzilla)
- CVE-2013-4533 qemu: pxa2xx: buffer overrun on incoming migration (Red Hat Bugzilla)
- CVE-2013-4534 qemu: openpic: buffer overrun on incoming migration (Red Hat Bugzilla)
- QEMU Homepage (QEMU)