ELSA-2014-0927 -- Oracle qemu-kvm, libcacard and qemu-guest-agentID: oval:org.secpod.oval:def:1500648 | Date: (C)2014-08-22 (M)2023-11-10 |
Class: PATCH | Family: unix |
Two integer overflow flaws were found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use either of these flaws to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Product: |
qemu-kvm |
libcacard |
qemu-guest-agent |