CVE-2012-6075
published 2013-02-13CVE-2012-6075: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.90%
91.5th percentile
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1.1.2+dfsg-4 (bookworm) | qemu 1.1.2+dfsg-4 (bookworm) |
| debian | xen | < qemu 1.1.2+dfsg-4 (bookworm) | qemu 1.1.2+dfsg-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | < 1.3.0 | 1.3.0 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-4 | 1.1.2+dfsg-4 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-4 | 1.1.2+dfsg-4 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-4 | 1.1.2+dfsg-4 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-4 | 1.1.2+dfsg-4 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerability
vendor_ubuntu·2013-01-16
CVE-2012-6075 QEMU vulnerability
Title: QEMU vulnerability
Summary: QEMU could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that QEMU incorrectly handled certain e1000 packet sizes.
In certain environments, an attacker may use this flaw in combination with
large packets to cause a denial of service or execute arbitrary code in the
guest.
Instructions: After a standard system update you need to restart your virtual machines to
make all the necessary changes.
Red Hat
qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
vendor_redhat·2012-12-16·CVSS 9.3
CVE-2012-6075 [CRITICAL] qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Package: kvm (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2012-6075: qemu - Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e10...
vendor_debian·2012·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075: qemu - Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e10...
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-4)
bullseye: resolved (fixed in 1.1.2+dfsg-4)
forky: resolved (fixed in 1.1.2+dfsg-4)
sid: resolved (fixed in 1.1.2+dfsg-4)
trixie: resolved (fixed in 1.1.2+dfsg-4)
GHSA
GHSA-mw8m-jhfq-5hv9: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000
ghsa_unreviewed·2022-05-13
CVE-2012-6075 [HIGH] CWE-120 GHSA-mw8m-jhfq-5hv9: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
OSV
CVE-2012-6075: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000
osv·2013-02-13·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075: Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
bugzilla·2013-02-13·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bod
Bugzilla
CVE-2012-6075 qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
bugzilla·2012-12-20·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075 qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
CVE-2012-6075 qemu: e1000 driver buffer overflow when processing large packets when SBP and LPE flags are disabled
A buffer overflow flaw was found in the way e1000 emulated device driver of QEMU, a FAST! processor emulator, processed received large e1000 packets, when the SBP and LPE flags were disabled. If the underlying network was configured to allow large (jumbo) packets, a remote attacker could use this flaw to cause relevant guest in question to crash (DoS) or, potentially, the attacker could use this flaw to execute arbitrary code on the guest system with the kernel level privilege.
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696051
[2] http://www.openwall.com/lists/oss-security/2012/12/19/9
[3] http://thread.gmane.org/gmane.comp.emulators.qemu/182666
[4] htt
Bugzilla
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
bugzilla·2012-12-20·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bod
Bugzilla
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [epel-5]
bugzilla·2012-12-20·CVSS 9.3
CVE-2012-6075 [CRITICAL] CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [epel-5]
CVE-2012-6075 qemu (e1000 device driver): Buffer overflow when processing large packets when SBP and LPE flags are disabled [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bo
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=b0d9ffcd0251161c7c92f94804dcf599dfa3edebhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097541.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097575.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097705.htmlhttp://lists.nongnu.org/archive/html/qemu-devel/2012-12/msg00533.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0599.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0608.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0609.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0610.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0639.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2013/dsa-2607http://www.debian.org/security/2013/dsa-2608http://www.debian.org/security/2013/dsa-2619http://www.openwall.com/lists/oss-security/2012/12/30/1http://www.securityfocus.com/bid/57420http://www.ubuntu.com/usn/USN-1692-1https://bugzilla.redhat.com/show_bug.cgi?id=889301http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=b0d9ffcd0251161c7c92f94804dcf599dfa3edebhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097541.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097575.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097705.htmlhttp://lists.nongnu.org/archive/html/qemu-devel/2012-12/msg00533.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0599.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0608.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0609.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0610.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0639.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2013/dsa-2607http://www.debian.org/security/2013/dsa-2608http://www.debian.org/security/2013/dsa-2619http://www.openwall.com/lists/oss-security/2012/12/30/1http://www.securityfocus.com/bid/57420http://www.ubuntu.com/usn/USN-1692-1https://bugzilla.redhat.com/show_bug.cgi?id=889301
2013-02-13
Published