Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.
References
Configurations
Configuration 1 (hide)
|
History
13 Feb 2023, 00:35
Type | Values Removed | Values Added |
---|---|---|
Summary | Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image. | |
References |
|
02 Feb 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary | CVE-2014-0182 qemu: virtio: out-of-bounds buffer write on state load with invalid config_len | |
References |
|
|
Information
Published : 2014-11-04 21:55
Updated : 2023-12-10 11:31
NVD link : CVE-2014-0182
Mitre link : CVE-2014-0182
CVE.ORG link : CVE-2014-0182
JSON object : View
Products Affected
qemu
- qemu
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer