First published: Tue Sep 06 2011(Updated: )
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=0.15.1 | |
QEMU KVM | =0.15.0-rc1 | |
QEMU KVM | =0.15.0-rc2 | |
Red Hat Enterprise Linux | =5 | |
Xen Xen |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.