PublicDateAtUSN: 2014-03-26 Candidate: CVE-2014-0145 PublicDate: 2017-08-10 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0145 http://www.openwall.com/lists/oss-security/2014/03/26 https://ubuntu.com/security/notices/USN-2342-1 Description: Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in the QCOW 2 block driver (block/qcow2-snapshot.c) or (2) uncompressed chunk, (3) chunk length, or (4) number of sectors in the DMG block driver (block/dmg.c). Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742730 Priority: medium Discovered-by: Stefan Hajnoczi Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_qemu-kvm: other: https://lists.gnu.org/archive/html/qemu-devel/2014-03/msg04994.html upstream_qemu-kvm: needs-triage lucid_qemu-kvm: released (0.12.3+noroms-0ubuntu9.24) precise_qemu-kvm: released (1.0+noroms-0ubuntu14.17) quantal_qemu-kvm: ignored (reached end-of-life) saucy_qemu-kvm: DNE trusty_qemu-kvm: DNE trusty/esm_qemu-kvm: DNE devel_qemu-kvm: DNE Patches_qemu: other: https://lists.gnu.org/archive/html/qemu-devel/2014-03/msg04994.html upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=c165f7758009a4f793c1fc19ebb69cf55313450b upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=c05e4667be91b46ab42b5a11babf8e84d476cc6b upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=f0dce23475b5af5da6b17b97c1765271307734b6 upstream_qemu: released (1.7.2, 2.0) lucid_qemu: DNE precise_qemu: DNE quantal_qemu: DNE saucy_qemu: ignored (reached end-of-life) trusty_qemu: not-affected (2.0.0~rc1+dfsg-0ubuntu3) trusty/esm_qemu: not-affected (2.0.0~rc1+dfsg-0ubuntu3) devel_qemu: not-affected (2.0.0~rc1+dfsg-0ubuntu3)