cbcvebase.
CVE-2011-3346
published 2014-04-01

CVE-2011-3346: Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the…

PriorityP413medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.49%
38.5th percentile
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.

Affected

3 ranges
VendorProductVersion rangeFixed in
qemuqemu<= 0.15.1
qemuqemu
redhatenterprise_linux

CVSS provenance

nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.