CVE-2012-6075

EUVD-2012-5949
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
qemuqemu
𝑥
< 1.3.0
opensuseopensuse
12.1
opensuseopensuse
12.2
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
5.9
redhatenterprise_linux_eus
6.4
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_aus
5.9
redhatenterprise_linux_server_aus
6.4
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
redhatvirtualization
3.0
debiandebian_linux
6.0
canonicalubuntu_linux
10.04
canonicalubuntu_linux
11.10
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qemu
bookworm
1:7.2+dfsg-7+deb12u7
fixed
bullseye
1:5.2+dfsg-11+deb11u3
fixed
bullseye (security)
1:5.2+dfsg-11+deb11u2
fixed
sid
1:9.1.1+ds-2
fixed
squeeze
not-affected
trixie
1:9.1.1+ds-2
fixed
xen
bookworm
4.17.3+10-g091466ba55-1~deb12u1
fixed
bullseye
4.14.6-1
fixed
bullseye (security)
4.14.5+94-ge49571868d-1
fixed
sid
4.17.3+36-g54dacb5c02-1
fixed
squeeze
not-affected
trixie
4.17.3+36-g54dacb5c02-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kvm
hardy
ignored
lucid
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
qemu
hardy
ignored
lucid
dne
oneiric
dne
precise
dne
quantal
dne
raring
Fixed 1.3.0+dfsg-1~exp3ubuntu3
released
saucy
Fixed 1.3.0+dfsg-1~exp3ubuntu3
released
qemu-kvm
hardy
dne
lucid
Fixed 0.12.3+noroms-0ubuntu9.21
released
oneiric
Fixed 0.14.1+noroms-0ubuntu6.6
released
precise
Fixed 1.0+noroms-0ubuntu14.7
released
quantal
Fixed 1.2.0+noroms-0ubuntu2.12.10.2
released
raring
dne
saucy
dne
xen
hardy
dne
lucid
dne
oneiric
Fixed 4.1.1-2ubuntu4.5
released
precise
Fixed 4.1.2-2ubuntu2.5
released
quantal
Fixed 4.1.3-3ubuntu1.2
released
raring
Fixed 4.2.0-1ubuntu6
released
saucy
Fixed 4.2.0-1ubuntu6
released
xen-3.1
hardy
ignored
lucid
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
xen-3.2
hardy
ignored
lucid
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
xen-3.3
hardy
dne
lucid
ignored
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
References