cbcvebase.
CVE-2012-6075
published 2013-02-13

CVE-2012-6075: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are…

critical9.3CVSS 3.1
AVNACMAuNCCICAC
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianqemu< qemu 1.1.2+dfsg-4 (bookworm)qemu 1.1.2+dfsg-4 (bookworm)
debianxen< qemu 1.1.2+dfsg-4 (bookworm)qemu 1.1.2+dfsg-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
qemuqemu< 1.3.01.3.0
qemuqemu>= 0 < 1.1.2+dfsg-41.1.2+dfsg-4
qemuqemu>= 0 < 1.1.2+dfsg-41.1.2+dfsg-4
qemuqemu>= 0 < 1.1.2+dfsg-41.1.2+dfsg-4
qemuqemu>= 0 < 1.1.2+dfsg-41.1.2+dfsg-4
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus

CVSS provenance

nvd9.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL