CVE-2013-4344Classic Buffer Overflow in Qemu

Severity
7.2HIGHNVD
EPSS
0.1%
top 79.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 13

Description

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages8 packages

Debianqemu/qemu< 1.6.0+dfsg-2+3
NVDqemu/qemu1.6.2
Debianxen/xen< 4.2-1+3
NVDopensuse/opensuse12.3, 13.1+1

Also affects: Ubuntu Linux 12.04, 12.10, 13.10

🔴Vulnerability Details

3
GHSA
GHSA-38mh-mg22-vw9h: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g2022-05-13
CVEList
CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g2013-10-04
OSV
CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to g2013-10-04

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2014-01-30
Red Hat
qemu: buffer overflow in scsi_target_emulate_report_luns2013-10-02
Debian
CVE-2013-4344: qemu - Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI ...2013

💬Community

4
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]2014-08-15
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]2013-10-03
Bugzilla
CVE-2013-4344 xen: qemu: buffer overflow in scsi_target_emulate_report_luns [fedora-all]2013-10-03
Bugzilla
CVE-2013-4344 qemu: buffer overflow in scsi_target_emulate_report_luns2013-09-12
CVE-2013-4344 — Classic Buffer Overflow in Qemu | cvebase