CVE-2014-3461

hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."
Configurations

Configuration 1 (hide)

cpe:2.3:a:qemu:qemu:1.6.2:*:*:*:*:*:*:*

History

13 Feb 2023, 00:39

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:1268', 'name': 'https://access.redhat.com/errata/RHSA-2014:1268', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0743', 'name': 'https://access.redhat.com/errata/RHSA-2014:0743', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-3461', 'name': 'https://access.redhat.com/security/cve/CVE-2014-3461', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0927', 'name': 'https://access.redhat.com/errata/RHSA-2014:0927', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0674', 'name': 'https://access.redhat.com/errata/RHSA-2014:0674', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1096821', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1096821', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0744', 'name': 'https://access.redhat.com/errata/RHSA-2014:0744', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0888', 'name': 'https://access.redhat.com/errata/RHSA-2014:0888', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2014-3461 Qemu: usb: fix up post load checks hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."

02 Feb 2023, 20:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2014:1268 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0743 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-3461 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0927 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0674 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1096821 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0744 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0888 -
Summary hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks." CVE-2014-3461 Qemu: usb: fix up post load checks

Information

Published : 2014-11-04 21:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-3461

Mitre link : CVE-2014-3461

CVE.ORG link : CVE-2014-3461


JSON object : View

Products Affected

qemu

  • qemu
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer