CVE-2014-0150 PUBLISHED

Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer overflow.

EPSS 0.55% · 67.8th percentile

Risk Scores

EPSS Score
0.55%
67.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSqemu0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6

Timeline

References

Open in Interactive Console →