Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2014-0223 | First vendor Publication | 2014-11-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.6 | Attack Range | Local |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0223 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:26667 | |||
Oval ID: | oval:org.mitre.oval:def:26667 | ||
Title: | RHSA-2014:1075: qemu-kvm security and bug fix update (Moderate) | ||
Description: | KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the user-space component for running virtual machines using KVM. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:1075-00 CESA-2014:1075 CVE-2014-0222 CVE-2014-0223 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | qemu-kvm |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26880 | |||
Oval ID: | oval:org.mitre.oval:def:26880 | ||
Title: | ELSA-2014-1075 -- qemu-kvm security and bug fix update (moderate) | ||
Description: | [0.12.1.2-2.415.el6_5.14] - The commit for zrelease .13 was incomplete; the changes to qemu-kvm.spec did not include the '%patchNNNN -p1' lines for patches 4647 through 4655; so although the patch files themselves were committed, the srpm build did not pick them up. In addition, the commit log did not describe the patches. This commit corrects these problems and bumps the zrelease to .14. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2014-1075 CVE-2014-0222 CVE-2014-0223 | Version: | 5 |
Platform(s): | Oracle Linux 6 | Product(s): | qemu-kvm |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2015-05-27 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-0929-1.nasl - Type : ACT_GATHER_INFO |
2015-03-19 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-061.nasl - Type : ACT_GATHER_INFO |
2014-11-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-220.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1076.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2014-1168.nasl - Type : ACT_GATHER_INFO |
2014-10-06 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3044.nasl - Type : ACT_GATHER_INFO |
2014-10-06 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3045.nasl - Type : ACT_GATHER_INFO |
2014-09-09 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2342-1.nasl - Type : ACT_GATHER_INFO |
2014-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-17.nasl - Type : ACT_GATHER_INFO |
2014-08-21 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1075.nasl - Type : ACT_GATHER_INFO |
2014-08-20 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1075.nasl - Type : ACT_GATHER_INFO |
2014-08-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1075.nasl - Type : ACT_GATHER_INFO |
2014-07-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-0927.nasl - Type : ACT_GATHER_INFO |
2014-07-26 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-0927.nasl - Type : ACT_GATHER_INFO |
2014-07-24 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-0927.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:38:31 |
|
2024-08-02 12:26:36 |
|
2024-08-02 01:07:58 |
|
2024-02-02 01:25:51 |
|
2024-02-01 12:07:41 |
|
2023-09-05 12:24:29 |
|
2023-09-05 01:07:35 |
|
2023-09-02 12:24:27 |
|
2023-09-02 01:07:41 |
|
2023-08-12 12:26:41 |
|
2023-08-12 01:07:11 |
|
2023-08-11 12:22:35 |
|
2023-08-11 01:07:21 |
|
2023-08-06 12:21:58 |
|
2023-08-06 01:07:10 |
|
2023-08-04 12:22:00 |
|
2023-08-04 01:07:14 |
|
2023-07-14 12:21:58 |
|
2023-07-14 01:07:13 |
|
2023-03-29 01:23:55 |
|
2023-03-28 12:07:34 |
|
2023-02-13 05:28:16 |
|
2023-02-03 00:28:30 |
|
2022-10-11 12:19:49 |
|
2022-10-11 01:07:22 |
|
2021-05-05 01:14:14 |
|
2021-05-04 12:29:23 |
|
2021-04-22 01:35:43 |
|
2020-11-03 09:22:45 |
|
2020-11-02 17:22:45 |
|
2020-05-24 01:13:12 |
|
2020-05-23 01:50:44 |
|
2020-05-23 00:39:23 |
|
2019-09-27 12:06:06 |
|
2018-09-07 12:07:25 |
|
2017-11-04 09:23:37 |
|
2016-11-29 00:24:51 |
|
2016-06-28 22:30:30 |
|
2016-05-03 13:30:31 |
|
2016-04-29 13:31:42 |
|
2016-04-27 00:03:58 |
|
2016-04-26 13:27:45 |
|
2015-12-05 13:26:30 |
|
2015-10-20 16:19:30 |
|
2015-10-18 17:27:06 |
|
2015-06-04 09:26:43 |
|
2015-05-28 13:27:46 |
|
2015-03-20 13:28:49 |
|
2015-03-14 13:25:22 |
|
2014-11-26 13:28:10 |
|
2014-11-08 13:31:31 |
|
2014-11-05 21:24:57 |
|
2014-11-05 05:29:49 |
|