CVE-2014-0142
published 2017-08-10CVE-2014-0142: QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the…
PriorityP416medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.38%
30.8th percentile
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.0.0+dfsg-1 (bookworm) | qemu 2.0.0+dfsg-1 (bookworm) |
| qemu | qemu | <= 2.0.0 | — |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.3 | 2.0.0+dfsg-2ubuntu1.3 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
qemu: crash by possible division by zero
vendor_redhat·2014-03-26·CVSS 5.5
CVE-2014-0142 [MEDIUM] CWE-369 qemu: crash by possible division by zero
qemu: crash by possible division by zero
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Debian
CVE-2014-0142: qemu - QEMU, possibly before 2.0.0, allows local users to cause a denial of service (di...
vendor_debian·2014·CVSS 5.5
CVE-2014-0142 [MEDIUM] CVE-2014-0142: qemu - QEMU, possibly before 2.0.0, allows local users to cause a denial of service (di...
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-1)
bullseye: resolved (fixed in 2.0.0+dfsg-1)
forky: resolved (fixed in 2.0.0+dfsg-1)
sid: resolved (fixed in 2.0.0+dfsg-1)
trixie: resolved (fixed in 2.0.0+dfsg-1)
GHSA
GHSA-cgcg-9vhg-7fq9: QEMU, possibly before 2
ghsa_unreviewed·2022-05-17
CVE-2014-0142 [MEDIUM] CWE-369 GHSA-cgcg-9vhg-7fq9: QEMU, possibly before 2
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
OSV
CVE-2014-0142: QEMU, possibly before 2
osv·2017-08-10·CVSS 5.5
CVE-2014-0142 [MEDIUM] CVE-2014-0142: QEMU, possibly before 2
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0142 qemu: crash by possible division by zero [fedora-all]
bugzilla·2014-04-11·CVSS 5.5
CVE-2014-0142 [MEDIUM] CVE-2014-0142 qemu: crash by possible division by zero [fedora-all]
CVE-2014-0142 qemu: crash by possible division by zero [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multi
Bugzilla
CVE-2014-0142 qemu: crash by possible division by zero
bugzilla·2014-03-19·CVSS 5.5
CVE-2014-0142 [MEDIUM] CVE-2014-0142 qemu: crash by possible division by zero
CVE-2014-0142 qemu: crash by possible division by zero
Qemu block drivers for parallels image and formats used by Bocsh are vulnerable
to a crash caused by possible division by zero error, in seek_to_sector routine.
It could occur if 's->tracks' & 's->extent_size' fields are 0. These are used
to derive 'index' and 'offset' values in seek_to_sector() routine.
An user able to alter the Qemu disk image could use this flaw to crash the
Qemu instance resulting in DoS.
Upstream fixes:
parallels: Sanity check for s->tracks
-> http://git.qemu.org/?p=qemu.git;a=commit;h=9302e863aa8baa5d932fc078967050c055fa1a7f
bochs: Check extent_size header field
-> http://git.qemu.org/?p=qemu.git;a=commit;h=8e53abbc20d08ae3ec30c2054e1161314ad9501d
Discussion:
Statement:
This issue affects the versions of k
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=8e53abbc20d08ae3ec30c2054e1161314ad9501dhttp://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9302e863aa8baa5d932fc078967050c055fa1a7fhttp://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.debian.org/security/2014/dsa-3044https://bugzilla.redhat.com/show_bug.cgi?id=1078201http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=8e53abbc20d08ae3ec30c2054e1161314ad9501dhttp://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9302e863aa8baa5d932fc078967050c055fa1a7fhttp://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.debian.org/security/2014/dsa-3044https://bugzilla.redhat.com/show_bug.cgi?id=1078201
2017-08-10
Published