CVE-2013-4375: Low severity qemu vulnerability
Published Jan 19, 2014
·Updated
The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.
Affected Software
10 affected components
Qemu Qemu=1.1
Qemu Qemu=1.1-rc1
Qemu Qemu=1.1-rc2
Qemu Qemu=1.1-rc3
Qemu Qemu=1.1-rc4
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
Event History
Jan 19, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4375?
CVE-2013-4375 is classified as a denial of service vulnerability.
2
How do I fix CVE-2013-4375?
To mitigate CVE-2013-4375, upgrade to QEMU version 1.1.1 or later and Xen versions 4.3.1 or later.
3
Which software is affected by CVE-2013-4375?
CVE-2013-4375 affects QEMU versions 1.1, including all release candidates, and Xen versions 4.2.x and 4.3.x prior to 4.3.1.
4
What type of attack does CVE-2013-4375 facilitate?
CVE-2013-4375 allows local HVM guests to cause a denial of service through domain grant reference consumption.
5
Is CVE-2013-4375 a local or remote vulnerability?
CVE-2013-4375 is a local vulnerability, allowing local attackers to exploit it.