CVE-2013-4538: Buffer Overflow
Multiple buffer overflows in the ssd0323load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmdlen, (2) row, or (3) col values; (4) rowstart and rowend values; or (5) colstar and colend values in a savevm image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4538?
CVE-2013-4538 has a high severity rating due to the potential for remote code execution and denial of service caused by multiple buffer overflows.
How do I fix CVE-2013-4538?
To mitigate CVE-2013-4538, update QEMU to version 1.7.2 or later where the vulnerabilities have been patched.
What software is affected by CVE-2013-4538?
CVE-2013-4538 affects multiple versions of QEMU prior to 1.7.2, including versions from 0.1.0 up to 1.7.1.
Can CVE-2013-4538 be exploited remotely?
Yes, CVE-2013-4538 can be exploited remotely by attackers sending crafted cmd_len, row, or col values to the vulnerable software.
What are the potential consequences of CVE-2013-4538 exploitation?
Exploitation of CVE-2013-4538 may lead to memory corruption, denial of service, or even full system compromise due to arbitrary code execution.