CVE-2013-4344
published 2013-10-04CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.43%
35.2th percentile
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | qemu | < qemu 1.6.0+dfsg-2 (bookworm) | qemu 1.6.0+dfsg-2 (bookworm) |
| debian | xen | < qemu 1.6.0+dfsg-2 (bookworm) | qemu 1.6.0+dfsg-2 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | <= 1.6.2 | — |
| qemu | qemu | >= 0 < 1.6.0+dfsg-2 | 1.6.0+dfsg-2 |
| qemu | qemu | >= 0 < 1.6.0+dfsg-2 | 1.6.0+dfsg-2 |
| qemu | qemu | >= 0 < 1.6.0+dfsg-2 | 1.6.0+dfsg-2 |
| qemu | qemu | >= 0 < 1.6.0+dfsg-2 | 1.6.0+dfsg-2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
| xen | xen | >= 0 < 4.2-1 | 4.2-1 |
| xen | xen | >= 0 < 4.2-1 | 4.2-1 |
| xen | xen | >= 0 < 4.2-1 | 4.2-1 |
| xen | xen | >= 0 < 4.2-1 | 4.2-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 7.2
CVE-2013-4344 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Asias He discovered that QEMU incorrectly handled SCSI controllers with
more than 256 attached devices. A local user could possibly use this flaw
to elevate privileges. (CVE-2013-4344)
It was discovered that QEMU incorrectly handled Xen disks. A local guest
could possibly use this flaw to consume resources, resulting in a denial of
service. This issue only affected Ubuntu 12.10 and Ubuntu 13.10.
(CVE-2013-4375)
Sibiao Luo discovered that QEMU incorrectly handled device hot-unplugging.
A local user could possibly use this flaw to cause a denial of service.
This issue only affected Ubuntu 13.10. (CVE-2013-4377)
Instructions: After a standard system update you need to reboot your computer to make
all the nec
Red Hat
qemu: buffer overflow in scsi_target_emulate_report_luns
vendor_redhat·2013-10-02·CVSS 7.2
CVE-2013-4344 [HIGH] qemu: buffer overflow in scsi_target_emulate_report_luns
qemu: buffer overflow in scsi_target_emulate_report_luns
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Statement: This issue does not affect the kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue does affect the qemu-kvm package as shipped with Red Hat Enterprise Linux 6. Future qemu-kvm updates in Red Hat Enterprise Linux 6 may address this flaw.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4344: qemu - Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI ...
vendor_debian·2013·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344: qemu - Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI ...
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
Scope: local
bookworm: resolved (fixed in 1.6.0+dfsg-2)
bullseye: resolved (fixed in 1.6.0+dfsg-2)
forky: resolved (fixed in 1.6.0+dfsg-2)
sid: resolved (fixed in 1.6.0+dfsg-2)
trixie: resolved (fixed in 1.6.0+dfsg-2)
GHSA
GHSA-38mh-mg22-vw9h: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g
ghsa_unreviewed·2022-05-13
CVE-2013-4344 [HIGH] CWE-120 GHSA-38mh-mg22-vw9h: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
OSV
CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g
osv·2013-10-04·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
bugzilla·2014-08-15·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
+++ This bug was initially created as a clone of Bug #1015275 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM change
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
bugzilla·2013-10-03·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this iss
Bugzilla
CVE-2013-4344 xen: qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
bugzilla·2013-10-03·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344 xen: qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
CVE-2013-4344 xen: qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns
bugzilla·2013-09-12·CVSS 7.2
CVE-2013-4344 [HIGH] CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns
A buffer overflow flaw was found in the way qemu processed SCSI REPORT LUNS command when excessive LUNS were defined for a single SCSI target.
A privileged guest user could use this flaw to corrupt qemu process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the qemu process.
Acknowledgements:
This issue was discovered by Asias He of Red Hat.
Discussion:
Statement:
This issue does not affect the kvm and xen packages as shipped with Red Hat Enterprise Linux 5.
This issue does affect the qemu-kvm package as shipped with Red Hat Enterprise Linux 6. Future qemu-kvm updates in Red Hat Enterprise Linux 6 may address this flaw.
---
This is now public:
http://article.gmane.org/gmane.comp.emulators.qemu/237191http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://osvdb.org/98028http://rhn.redhat.com/errata/RHSA-2013-1553.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1754.htmlhttp://www.openwall.com/lists/oss-security/2013/10/02/2http://www.securityfocus.com/bid/62773http://www.ubuntu.com/usn/USN-2092-1http://article.gmane.org/gmane.comp.emulators.qemu/237191http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://osvdb.org/98028http://rhn.redhat.com/errata/RHSA-2013-1553.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1754.htmlhttp://www.openwall.com/lists/oss-security/2013/10/02/2http://www.securityfocus.com/bid/62773http://www.ubuntu.com/usn/USN-2092-1
2013-10-04
Published