Back to search
CVE-2014-0145
Published: Aug 10, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in the QCOW 2 block driver (block/qcow2-snapshot.c) or (2) uncompressed chunk, (3) chunk length, or (4) number of sectors in the DMG block driver (block/dmg.c).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2014:0420
vendor-advisory
x_refsource_REDHAT
RHSA-2014:0421
vendor-advisory
x_refsource_REDHAT
DSA-3044
vendor-advisory
x_refsource_DEBIAN
https://bugzilla.redhat.com/show_bug.cgi?id=1078885
x_refsource_CONFIRM
[oss-security] 20140326 QEMU image format input validation fixes (multiple CVEs)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now