CVE-2013-4149: Buffer Overflow
Published Nov 4, 2014
·Updated
Buffer overflow in virtionetload function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbitrary code via a large MAC table.
Affected Software
21 affected components
Qemu Qemu=1.3.0
Qemu Qemu=1.3.0-rc0
Qemu Qemu=1.3.0-rc1
Qemu Qemu=1.3.0-rc2
Qemu Qemu=1.3.1
Qemu Qemu=1.4.1
Qemu Qemu=1.4.2
Qemu Qemu=1.5.0
Qemu Qemu=1.5.0-rc1
Qemu Qemu=1.5.0-rc2
Qemu Qemu=1.5.0-rc3
Qemu Qemu=1.5.1
Qemu Qemu=1.5.2
Qemu Qemu=1.5.3
Qemu Qemu=1.6.0
Qemu Qemu=1.6.0-rc1
Qemu Qemu=1.6.0-rc2
Qemu Qemu=1.6.0-rc3
Qemu Qemu=1.6.1
Qemu Qemu=1.6.2
Qemu Qemu=1.7.1
Remediation
Patch Available
Event History
Nov 4, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4149?
CVE-2013-4149 has a high severity rating due to the potential for remote code execution via a buffer overflow.
2
How do I fix CVE-2013-4149?
To fix CVE-2013-4149, upgrade QEMU to version 1.7.2 or later where the vulnerability is addressed.
3
What versions of QEMU are affected by CVE-2013-4149?
CVE-2013-4149 affects QEMU versions 1.3.0 through 1.7.1, including all release candidates in those ranges.
4
What is the nature of the vulnerability in CVE-2013-4149?
CVE-2013-4149 is a buffer overflow vulnerability that allows attackers to execute arbitrary code via a large MAC table.
5
Can exploiting CVE-2013-4149 compromise my system?
Yes, exploiting CVE-2013-4149 can lead to system compromise and unauthorized execution of code.