Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
13 Feb 2023, 00:37
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image. |
02 Feb 2023, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary | An integer overflow flaw was found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use this flaw to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process. | |
References |
|
Information
Published : 2014-11-04 21:55
Updated : 2023-12-10 11:31
NVD link : CVE-2014-0222
Mitre link : CVE-2014-0222
CVE.ORG link : CVE-2014-0222
JSON object : View
Products Affected
qemu
- qemu
suse
- linux_enterprise_server
CWE
CWE-189
Numeric Errors