CVE-2013-4344: Buffer Overflow
Published Oct 4, 2013
·Updated
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Affected Software
11 affected components
Qemu Qemu<=1.6.2
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
redhat Virtualization=3.0
redhat Enterprise Linux=6.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.10
Event History
Oct 4, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4344?
CVE-2013-4344 has a severity rating of medium due to its potential for local privilege escalation.
2
How do I fix CVE-2013-4344?
To fix CVE-2013-4344, you should update your QEMU software to a version higher than 1.6.2.
3
Which software is affected by CVE-2013-4344?
CVE-2013-4344 affects QEMU versions up to 1.6.2 and specific releases of openSUSE, Red Hat Enterprise Linux, and Ubuntu.
4
Can CVE-2013-4344 be exploited remotely?
CVE-2013-4344 is a local privilege escalation vulnerability and cannot be exploited remotely.
5
What impact does CVE-2013-4344 have on systems?
CVE-2013-4344 can allow local users to gain elevated privileges on the affected systems.