First published: Mon Oct 16 2017(Updated: )
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <=2.4.1 | |
QEMU qemu | =2.5.0-rc0 | |
QEMU qemu | =2.5.0-rc1 | |
QEMU qemu | =2.5.0-rc2 | |
Xen Xen | ||
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.