CVE-2013-4150: Buffer Overflow
Published Nov 4, 2014
·Updated
The virtionetload function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of currqueues is greater than maxqueues, which triggers an out-of-bounds write.
Affected Software
14 affected components
Qemu Qemu=1.5.0
Qemu Qemu=1.5.0-rc1
Qemu Qemu=1.5.0-rc2
Qemu Qemu=1.5.0-rc3
Qemu Qemu=1.5.1
Qemu Qemu=1.5.2
Qemu Qemu=1.5.3
Qemu Qemu=1.6.0
Qemu Qemu=1.6.0-rc1
Qemu Qemu=1.6.0-rc2
Qemu Qemu=1.6.0-rc3
Qemu Qemu=1.6.1
Qemu Qemu=1.6.2
Qemu Qemu=1.7.1
Remediation
Patch Available
Event History
Nov 4, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4150?
The severity of CVE-2013-4150 is considered high due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2013-4150?
To fix CVE-2013-4150, upgrade QEMU to version 1.7.2 or later.
3
Which versions of QEMU are affected by CVE-2013-4150?
CVE-2013-4150 affects QEMU versions 1.5.0 through 1.7.1.
4
What type of vulnerability is CVE-2013-4150?
CVE-2013-4150 is an out-of-bounds write vulnerability in the virtio_net_load function.
5
Can CVE-2013-4150 be exploited remotely?
Yes, CVE-2013-4150 can be exploited remotely, leading to denial of service and possible execution of malicious code.