CVE-2014-0223
published 2014-11-04CVE-2014-0223: Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute…
PriorityP421medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.60%
45.4th percentile
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.0.0+dfsg-6 (bookworm) | qemu 2.0.0+dfsg-6 (bookworm) |
| qemu | qemu | <= 1.7.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat7.4HIGH
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qpid-proton: TLS Man in the Middle Vulnerability
vendor_redhat·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CWE-358 qpid-proton: TLS Man in the Middle Vulnerability
qpid-proton: TLS Man in the Middle Vulnerability
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
A cryptographic weakness was discovered in qpid-proton's use of TLS. If the qpid-proton client was used without client certificates, it would accept an anonymous cipher offered by the server. A man-in-the-middle attacker could use this to silently intercept traffic that should have been encrypted.
Statement: Red
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
Qemu: qcow1: validate image size to avoid out-of-bounds memory access
vendor_redhat·2014-05-12·CVSS 4.6
CVE-2014-0223 [MEDIUM] CWE-190 Qemu: qcow1: validate image size to avoid out-of-bounds memory access
Qemu: qcow1: validate image size to avoid out-of-bounds memory access
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
An integer overflow flaw was found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use this flaw to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2014-0223: qemu - Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 ...
vendor_debian·2014·CVSS 4.6
CVE-2014-0223 [MEDIUM] CVE-2014-0223: qemu - Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 ...
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-6)
bullseye: resolved (fixed in 2.0.0+dfsg-6)
forky: resolved (fixed in 2.0.0+dfsg-6)
sid: resolved (fixed in 2.0.0+dfsg-6)
trixie: resolved (fixed in 2.0.0+dfsg-6)
GHSA
Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
ghsa·2022-05-24
CVE-2019-0223 [HIGH] CWE-295 Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
## Withdrawn Advisory
This advisory has been withdrawn because the vulnerability only affects the **Qpid Proton C library** and not `org.apache.qpid:proton-j`. This link has been maintained to preserve external references.
## Original Description
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
GHSA
GHSA-234q-mv7h-px9x: Integer overflow in the qcow_open function in block/qcow
ghsa_unreviewed·2022-05-13
CVE-2014-0223 [MEDIUM] GHSA-234q-mv7h-px9x: Integer overflow in the qcow_open function in block/qcow
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
OSV
CVE-2014-0223: Integer overflow in the qcow_open function in block/qcow
osv·2014-11-04·CVSS 4.6
CVE-2014-0223 [MEDIUM] CVE-2014-0223: Integer overflow in the qcow_open function in block/qcow
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access [fedora-all]
bugzilla·2014-05-13·CVSS 4.6
CVE-2014-0223 [MEDIUM] CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access [fedora-all]
CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issu
Bugzilla
CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access
bugzilla·2014-05-13·CVSS 4.6
CVE-2014-0223 [MEDIUM] CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access
CVE-2014-0223 Qemu: qcow1: validate image size to avoid out-of-bounds memory access
Qemu block driver for the QCOW version 1 image format is vulnerable to an
integer overflow flaw. It occurs due to weak input validations or logic errors.
Such integer overflow could lead to buffer overflows, memory corruption or
crash in Qemu instance.
An user able to alter the Qemu disk image files loaded by a guest could use
this flaw to crash the Qemu instance resulting in DoS or corrupt QEMU process
memory on the host, which could potentially result in arbitrary code execution
on the host with the privileges of the QEMU process.
Upstream fix:
-> https://lists.gnu.org/archive/html/qemu-devel/2014-05/msg02156.html
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 109723
Talos
Vulnerability Spotlight - LibBPG Image Decoding Code Execution
blogs_talos·2017-01-23·CVSS 7.8
CVE-2016-8710 [HIGH] Vulnerability Spotlight - LibBPG Image Decoding Code Execution
Discovered by Cisco Talos
### Overview
Talos is disclosing TALOS-2016-0223 / CVE-2016-8710. An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using libbpg.
### Details
BPG (Better Portable Graphics) is an image format created in 2014 based on the HECV video compression standard. BPG has been praised for its ability to produce the same quality image as the well known JPEG format, but in a much smaller file size. Talos is disclosing the presence of a remote code execution vulnerability in the libbpg
Talos
Vulnerability Spotlight - LibBPG Image Decoding Code Execution
blogs_talos·2017-01-23·CVSS 7.8
CVE-2016-8710 [HIGH] Vulnerability Spotlight - LibBPG Image Decoding Code Execution
## Vulnerability Spotlight - LibBPG Image Decoding Code Execution
Discovered by Cisco Talos
## Overview
Talos is disclosing TALOS-2016-0223 / CVE-2016-8710. An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code execution. This vulnerability can be triggered via attempting to decode a crafted BPG image using libbpg.
## Details
BPG (Better Portable Graphics) is an image format created in 2014 based on the HECV video compression standard. BPG has been praised for its ability to produce the same quality image as the well known JPEG format, but in a much smaller file size. Talos is disclosing th
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134053.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.htmlhttp://www.debian.org/security/2014/dsa-3044http://www.securityfocus.com/bid/67391https://lists.gnu.org/archive/html/qemu-devel/2014-05/msg02156.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134053.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.htmlhttp://www.debian.org/security/2014/dsa-3044http://www.securityfocus.com/bid/67391https://lists.gnu.org/archive/html/qemu-devel/2014-05/msg02156.html
2014-11-04
Published