The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
2014-11-07T19:55:02.713
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 7.0 | Yes |
Application | qemu | qemu | 2.0.0 | Yes |
Application | qemu | qemu | 2.0.0 | Yes |
Application | qemu | qemu | 2.0.0 | Yes |
Application | qemu | qemu | 2.0.0 | Yes |
Application | qemu | qemu | 2.0.0 | Yes |
Application | qemu | qemu | 2.0.2 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.0 | Yes |
Application | qemu | qemu | 2.1.1 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_hpc_node | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Operating System | canonical | ubuntu_linux | 10.04 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.10 | Yes |