cbcvebase.
CVE-2011-4111
published 2014-02-26

CVE-2011-4111: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers…

PriorityP430medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
2.26%
81.1th percentile
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 0.15.1+dfsg-2 (bookworm)qemu 0.15.1+dfsg-2 (bookworm)
debianxen< qemu 0.15.1+dfsg-2 (bookworm)qemu 0.15.1+dfsg-2 (bookworm)
qemuqemu<= 0.15.1
qemuqemu
qemuqemu
qemuqemu>= 0 < 0.15.1+dfsg-20.15.1+dfsg-2
qemuqemu>= 0 < 0.15.1+dfsg-20.15.1+dfsg-2
qemuqemu>= 0 < 0.15.1+dfsg-20.15.1+dfsg-2
qemuqemu>= 0 < 0.15.1+dfsg-20.15.1+dfsg-2
redhatenterprise_linux
redhatenterprise_linux_server_supplementary
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1

CVSS provenance

nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.