Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2014-8106
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 4.6/10
- Exploit Score
- 3.9/10
- Access Vector
- Local
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 6.4/10
- Confidentiality Impact
- Partial
- Availability Impact
- Partial
- Integrity Impact
- Partial
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:qemu:qemu:2.1.0:rc2:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.0:rc3:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.0:rc1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.0:rc5:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:qemu:qemu:2.1.0:rc0:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://lists.gnu.org/archive/html/qemu-devel/2014-12/msg00508.html
- http://www.securityfocus.com/bid/71477
- http://www.debian.org/security/2014/dsa-3088
- http://www.openwall.com/lists/oss-security/2014/12/04/8
- http://www.debian.org/security/2014/dsa-3087
- http://secunia.com/advisories/60364
- http://rhn.redhat.com/errata/RHSA-2015-0643.html
- http://rhn.redhat.com/errata/RHSA-2015-0349.html
- http://rhn.redhat.com/errata/RHSA-2015-0624.html
- http://rhn.redhat.com/errata/RHSA-2015-0795.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154656.html
- http://support.citrix.com/article/CTX200892
- http://rhn.redhat.com/errata/RHSA-2015-0891.html
- http://rhn.redhat.com/errata/RHSA-2015-0868.html
- http://rhn.redhat.com/errata/RHSA-2015-0867.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99126
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=bf25983345ca44aec3dd92c57142be45452bd38a
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=d3532a0db02296e687711b8cdc7791924efccea0