CVE-2011-3346
published 2014-04-01CVE-2011-3346: Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the…
PriorityP413medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.49%
38.5th percentile
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qemu | qemu | <= 0.15.1 | — |
| qemu | qemu | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qemu: local DoS with SCSI CD-ROM
vendor_redhat·2011-09-07·CVSS 4.0
CVE-2011-3346 [MEDIUM] qemu: local DoS with SCSI CD-ROM
qemu: local DoS with SCSI CD-ROM
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
Statement: This issue only affects qemu as shipped with Red Hat Enterprise Linux 5 xen packages. The versions of the qemu/kvm as shipped with Red Hat Enterprise Linux 5 are not affected.
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: xen (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
GHSA
GHSA-q6jm-gv84-4cp6: Buffer overflow in hw/scsi-disk
ghsa_unreviewed·2022-05-17
CVE-2011-3346 [MEDIUM] CWE-119 GHSA-q6jm-gv84-4cp6: Buffer overflow in hw/scsi-disk
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
No detection rules found.
No public exploits indexed.
http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://www.openwall.com/lists/oss-security/2011/10/20/2http://www.redhat.com/support/errata/RHSA-2011-1401.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=736038https://github.com/bonzini/qemu/commit/103b40f51e4012b3b0ad20f615562a1806d7f49ahttps://github.com/bonzini/qemu/commit/7285477ab11831b1cf56e45878a89170dd06d9b9http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://www.openwall.com/lists/oss-security/2011/10/20/2http://www.redhat.com/support/errata/RHSA-2011-1401.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=736038https://github.com/bonzini/qemu/commit/103b40f51e4012b3b0ad20f615562a1806d7f49ahttps://github.com/bonzini/qemu/commit/7285477ab11831b1cf56e45878a89170dd06d9b9
2014-04-01
Published