QEMU 'arch_init.c' Local Memory Corruption Vulnerability
BID:71658
Info
QEMU 'arch_init.c' Local Memory Corruption Vulnerability
| Bugtraq ID: | 71658 |
| Class: | Unknown |
| CVE: |
CVE-2014-7840 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 11 2014 12:00AM |
| Updated: | Apr 13 2015 08:23PM |
| Credit: | Michael S. Tsirkin |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 QEMU QEMU 0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
QEMU 'arch_init.c' Local Memory Corruption Vulnerability
QEMU is prone to a local memory-corruption vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code on the host with the privileges of the QEMU process. Failed attacks may cause a denial-of-service condition.
QEMU is prone to a local memory-corruption vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code on the host with the privileges of the QEMU process. Failed attacks may cause a denial-of-service condition.
Exploit / POC
QEMU 'arch_init.c' Local Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
QEMU 'arch_init.c' Local Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva qemu-1.6.2-1.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva qemu-img-1.6.2-1.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
QEMU 'arch_init.c' Local Memory Corruption Vulnerability
References:
References:
- [PATCH 0/4] migration: fix CVE-2014-7840 (Michael S. Tsirkin)
- Bug 1163075 - (CVE-2014-7840) CVE-2014-7840 qemu: insufficient parameter validat (Red Hat Bugzilla)
- migration: fix parameter validation on ram load (QEMU)
- QEMU Homepage (QEMU)