CVE 2013-4148
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
Related bugs and status
CVE-2013-4148 (Candidate) is related to these bugs:
Bug #1322204: image format input validation fixes tracking bug
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu) | Undecided | Fix Released | ||
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu Utopic) | Undecided | Fix Released | ||
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu Saucy) | Undecided | Won't Fix | ||
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu Trusty) | Undecided | Fix Released | ||
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu Lucid) | Undecided | Invalid | ||
1322204 | image format input validation fixes tracking bug | qemu (Ubuntu Precise) | Undecided | Invalid | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu) | Undecided | Invalid | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu Lucid) | Undecided | Fix Released | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu Precise) | Undecided | Fix Released | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu Saucy) | Undecided | Invalid | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu Trusty) | Undecided | Invalid | ||
1322204 | image format input validation fixes tracking bug | qemu-kvm (Ubuntu Utopic) | Undecided | Invalid |
See the
CVE page on Mitre.org
for more details.