CVE-2014-2894: High severity Qemu Qemu vulnerability
Off-by-one error in the cmdsmart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2894?
CVE-2014-2894 is classified as a medium severity vulnerability due to its potential for causing buffer underflows and memory corruption.
How do I fix CVE-2014-2894?
To resolve CVE-2014-2894, you should update QEMU to version 2.0 or later, where the vulnerability has been patched.
Who is affected by CVE-2014-2894?
Local users of QEMU versions prior to 2.0, specifically older than version 1.7.1, are at risk from CVE-2014-2894.
What specific function is vulnerable in CVE-2014-2894?
CVE-2014-2894 affects the cmd_smart function in the smart self-test in the hw/ide/core.c file of QEMU.
What can an attacker do with CVE-2014-2894?
An attacker exploiting CVE-2014-2894 can potentially trigger a buffer underflow that leads to system instability or unauthorized access.