CVE-2012-0029
published 2012-01-27CVE-2012-0029: Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS…
PriorityP334high7.4CVSS 2.0
AVAACMAuSCCICAC
EPSS
0.92%
56.4th percentile
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm) | xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm) |
| kvm_group | qemu-kvm | — | — |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
CVSS provenance
nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
osv7.4HIGH
vendor_debian7.4MEDIUM
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8rxf-mc82-x3wv: Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000
ghsa_unreviewed·2022-05-04
CVE-2012-0029 [HIGH] CWE-119 GHSA-8rxf-mc82-x3wv: Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
OSV
CVE-2012-0029: Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000
osv·2012-01-27·CVSS 7.4
CVE-2012-0029 [HIGH] CVE-2012-0029: Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
Ubuntu
QEMU vulnerability
vendor_ubuntu·2012-01-23
CVE-2012-0029 QEMU vulnerability
Title: QEMU vulnerability
Summary: A remote attacker could cause QEMU to crash.
Nicolae Mogoreanu discovered that QEMU did not properly verify legacy mode
packets in the e1000 network driver. A remote attacker could exploit this
to cause a denial of service or possibly execute code with the privileges
of the user invoking the program.
When using QEMU with libvirt or virtualization management software based on
libvirt such as Eucalyptus and OpenStack, QEMU guests are individually
isolated by an AppArmor profile by default in Ubuntu.
Instructions: After a standard system update you need to restart running virtual machines
which use the e1000 network driver to make all the necessary changes.
Red Hat
qemu: e1000: process_tx_desc legacy mode packets heap overflow
vendor_redhat·2012-01-23·CVSS 7.4
CVE-2012-0029 [HIGH] CWE-228 qemu: e1000: process_tx_desc legacy mode packets heap overflow
qemu: e1000: process_tx_desc legacy mode packets heap overflow
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
Package: kvm (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2012-0029: xen - Heap-based buffer overflow in the process_tx_desc function in the e1000 emulatio...
vendor_debian·2012·CVSS 7.4
CVE-2012-0029 [HIGH] CVE-2012-0029: xen - Heap-based buffer overflow in the process_tx_desc function in the e1000 emulatio...
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
Scope: local
bookworm: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
bullseye: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
forky: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
sid: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
trixie: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
bugzilla·2012-05-29·CVSS 7.4
CVE-2012-0029 [HIGH] CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
Clone for F16
+++ This bug was initially created as a clone of Bug #783984 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when a
Bugzilla
CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
bugzilla·2012-01-23·CVSS 7.4
CVE-2012-0029 [HIGH] CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
CVE-2012-0029 qemu-kvm: e1000: process_tx_desc legacy mode packets heap overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/n
Bugzilla
CVE-2012-0029 qemu: e1000: process_tx_desc legacy mode packets heap overflow
bugzilla·2012-01-05·CVSS 7.4
CVE-2012-0029 [HIGH] CVE-2012-0029 qemu: e1000: process_tx_desc legacy mode packets heap overflow
CVE-2012-0029 qemu: e1000: process_tx_desc legacy mode packets heap overflow
There isn't proper checking in legacy mode packets such that if two large
packets arrive back to back without the EOP flag set in the first packet, you
can easily overrun your buffer.
Because data is written to the packets after the packet is processed, this
could allow a heap overflow which is exploitable.
Acknowledgements:
Red Hat would like to thank Nicolae Mogoreanu for reporting this issue.
Discussion:
This issue did affect the versions of xen package as shipped with Red Hat
Enterprise Linux 5.
This issue did affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue did affect the versions of qemu-kvm package as shipped with Red Hat
Enterprise Linux 6.
---
Created qem
http://git.qemu.org/?p=qemu.git%3Ba=log%3Bh=refs/heads/stable-1.0http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081972.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-02/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0370.htmlhttp://secunia.com/advisories/47740http://secunia.com/advisories/47741http://secunia.com/advisories/47992http://secunia.com/advisories/48318http://secunia.com/advisories/50913http://www.redhat.com/support/errata/RHSA-2012-0050.htmlhttp://www.securityfocus.com/bid/51642http://www.ubuntu.com/usn/USN-1339-1https://bugzilla.redhat.com/show_bug.cgi?id=772075https://exchange.xforce.ibmcloud.com/vulnerabilities/72656http://git.qemu.org/?p=qemu.git%3Ba=log%3Bh=refs/heads/stable-1.0http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081972.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-02/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0370.htmlhttp://secunia.com/advisories/47740http://secunia.com/advisories/47741http://secunia.com/advisories/47992http://secunia.com/advisories/48318http://secunia.com/advisories/50913http://www.redhat.com/support/errata/RHSA-2012-0050.htmlhttp://www.securityfocus.com/bid/51642http://www.ubuntu.com/usn/USN-1339-1https://bugzilla.redhat.com/show_bug.cgi?id=772075https://exchange.xforce.ibmcloud.com/vulnerabilities/72656
2012-01-27
Published