CVE-2013-4344
04.10.2013, 17:55
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 𝑥 ≤ 1.6.2 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | virtualization | 3.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.10 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||||
| xen |
|
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||
| qemu-kvm |
| ||||||||||
| xen |
| ||||||||||
| xen-3.3 |
|
References