CVE-2012-6075
13.02.2013, 01:55
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 𝑥 < 1.3.0 |
| opensuse | opensuse | 12.1 |
| opensuse | opensuse | 12.2 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 5.9 |
| redhat | enterprise_linux_eus | 6.4 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 5.9 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | virtualization | 3.0 |
| debian | debian_linux | 6.0 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 11.10 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||||
| xen |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| kvm |
| ||||||||||||||
| qemu |
| ||||||||||||||
| qemu-kvm |
| ||||||||||||||
| xen |
| ||||||||||||||
| xen-3.1 |
| ||||||||||||||
| xen-3.2 |
| ||||||||||||||
| xen-3.3 |
|
References