CVE-2013-4344
04.10.2013, 17:55
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Vendor | Product | Version |
---|---|---|
qemu | qemu | 𝑥 ≤ 1.6.2 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 6.0 |
redhat | virtualization | 3.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
canonical | ubuntu_linux | 13.10 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
qemu |
| ||||||||||||
xen |
|

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
qemu |
| ||||||||||
qemu-kvm |
| ||||||||||
xen |
| ||||||||||
xen-3.3 |
|
References