CVE-2014-0223 — Integer Overflow or Wraparound in Qemu
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 73.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 4
Latest updateMay 24
Description
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4Debian▶
CVE-2014-0223: qemu - Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 ...↗2014