CVE-2011-4111
published 2014-02-26CVE-2011-4111: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers…
PriorityP430medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
2.26%
81.1th percentile
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 0.15.1+dfsg-2 (bookworm) | qemu 0.15.1+dfsg-2 (bookworm) |
| debian | xen | < qemu 0.15.1+dfsg-2 (bookworm) | qemu 0.15.1+dfsg-2 (bookworm) |
| qemu | qemu | <= 0.15.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.15.1+dfsg-2 | 0.15.1+dfsg-2 |
| qemu | qemu | >= 0 < 0.15.1+dfsg-2 | 0.15.1+dfsg-2 |
| qemu | qemu | >= 0 < 0.15.1+dfsg-2 | 0.15.1+dfsg-2 |
| qemu | qemu | >= 0 < 0.15.1+dfsg-2 | 0.15.1+dfsg-2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4c3m-mrr2-fw4x: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru
ghsa_unreviewed·2022-05-14
CVE-2011-4111 [MEDIUM] CWE-119 GHSA-4c3m-mrr2-fw4x: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
OSV
CVE-2011-4111: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru
osv·2014-02-26·CVSS 6.8
CVE-2011-4111 [MEDIUM] CVE-2011-4111: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Red Hat
qemu: ccid: buffer overflow in handling of VSC_ATR message
vendor_redhat·2011-11-28·CVSS 6.8
CVE-2011-4111 [MEDIUM] qemu: ccid: buffer overflow in handling of VSC_ATR message
qemu: ccid: buffer overflow in handling of VSC_ATR message
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Statement: This issue does not affect versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
Debian
CVE-2011-4111: qemu - Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-...
vendor_debian·2011·CVSS 6.8
CVE-2011-4111 [MEDIUM] CVE-2011-4111: qemu - Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-...
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Scope: local
bookworm: resolved (fixed in 0.15.1+dfsg-2)
bullseye: resolved (fixed in 0.15.1+dfsg-2)
forky: resolved (fixed in 0.15.1+dfsg-2)
sid: resolved (fixed in 0.15.1+dfsg-2)
trixie: resolved (fixed in 0.15.1+dfsg-2)
Suricata
ET WEB_SPECIFIC_APPS HP Insight Diagnostics Online Edition search.php XSS Attempt
suricata·2011-06-09
CVE-2010-4111 ET WEB_SPECIFIC_APPS HP Insight Diagnostics Online Edition search.php XSS Attempt
ET WEB_SPECIFIC_APPS HP Insight Diagnostics Online Edition search.php XSS Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS HP Insight Diagnostics Online Edition search.php XSS Attempt"; flow:established,to_server; http.uri; content:"/hpdiags/frontend2/help/search.php?query="; nocase; pcre:"/^.+(?:script|alert|onmouse[a-z]+|onkey[a-z]+|onload|onunload|ondragdrop|onblur|onfocus|onclick|ondblclick|onsubmit|onreset|onselect|onchange)/Ri"; reference:bid,45420; reference:cve,2010-4111; classtype:web-application-attack; sid:2012976; rev:3; metadata:created_at 2011_06_09, cve CVE_2010_4111, signature_severity Major, updated_at 2020_04_20;)
No public exploits indexed.
http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://git.qemu.org/?p=qemu.git%3Ba=log%3Bh=refs/heads/stable-1.0http://rhn.redhat.com/errata/RHSA-2011-1777.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1801.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=751310http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://git.qemu.org/?p=qemu.git%3Ba=log%3Bh=refs/heads/stable-1.0http://rhn.redhat.com/errata/RHSA-2011-1777.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1801.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=751310
2014-02-26
Published