Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
2013-02-13T01:55:03.027
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | < 1.3.0 | Yes |
Operating System | fedoraproject | fedora | 16 | Yes |
Operating System | fedoraproject | fedora | 17 | Yes |
Operating System | fedoraproject | fedora | 18 | Yes |
Operating System | opensuse | opensuse | 12.1 | Yes |
Operating System | opensuse | opensuse | 12.2 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | redhat | enterprise_linux_desktop | 5.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 6.0 | Yes |
Operating System | redhat | enterprise_linux_eus | 5.9 | Yes |
Operating System | redhat | enterprise_linux_eus | 6.4 | Yes |
Operating System | redhat | enterprise_linux_server | 5.0 | Yes |
Operating System | redhat | enterprise_linux_server | 6.0 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 5.9 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 6.4 | Yes |
Operating System | redhat | enterprise_linux_workstation | 5.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 6.0 | Yes |
Application | redhat | virtualization | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | No |
Operating System | debian | debian_linux | 6.0 | Yes |
Operating System | canonical | ubuntu_linux | 10.04 | Yes |
Operating System | canonical | ubuntu_linux | 11.10 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 12.10 | Yes |