[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80167

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-14167

Date: (C)2017-09-11   (M)2017-12-29 


Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write.

CVSS Score: 7.2Access Vector: LOCAL
Exploit Score: 3.9Access Complexity: LOW
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
BID-100694
DSA-3991
RHSA-2017:3368
RHSA-2017:3369
RHSA-2017:3466
RHSA-2017:3470
RHSA-2017:3471
RHSA-2017:3472
RHSA-2017:3473
RHSA-2017:3474
http://www.openwall.com/lists/oss-security/2017/09/07/2
https://lists.nongnu.org/archive/html/qemu-devel/2017-09/msg01032.html

CPE    1
cpe:/a:qemu:qemu
CWE    1
CWE-787
OVAL    6
oval:org.secpod.oval:def:502202
oval:org.secpod.oval:def:204717
oval:org.secpod.oval:def:1600817
oval:org.secpod.oval:def:113402
...

© 2013 SecPod Technologies