CVE-2013-4533: Buffer Overflow
Buffer overflow in the pxa2xxsspload function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rxlevel value in a savevm image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4533?
CVE-2013-4533 has a severity rating that could range from low to high depending on the context, primarily resulting in denial of service or potential remote code execution.
How do I fix CVE-2013-4533?
To fix CVE-2013-4533, upgrade to QEMU version 1.7.2 or later.
What kind of attack can exploit CVE-2013-4533?
CVE-2013-4533 can be exploited by remote attackers using a crafted s->rx_level value in a savevm image to perform denial of service or execute arbitrary code.
Which versions of QEMU are affected by CVE-2013-4533?
CVE-2013-4533 affects QEMU versions prior to 1.7.2 as well as all 0.x versions up to 1.7.1.
What is the component affected in CVE-2013-4533?
The vulnerability in CVE-2013-4533 specifically affects the pxa2xx_ssp_load function in the hw/arm/pxa2xx.c file of QEMU.