Vulnerability Description
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | <= 0.15.1 |
| Redhat | Enterprise Linux | 5 |
| Xen | Xen | - |
Related Weaknesses (CWE)
References
- http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=log
- http://www.openwall.com/lists/oss-security/2011/10/20/2
- http://www.redhat.com/support/errata/RHSA-2011-1401.html
- https://bugzilla.redhat.com/show_bug.cgi?id=736038
- https://github.com/bonzini/qemu/commit/103b40f51e4012b3b0ad20f615562a1806d7f49aExploitPatch
- https://github.com/bonzini/qemu/commit/7285477ab11831b1cf56e45878a89170dd06d9b9ExploitPatch
- http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=log
- http://www.openwall.com/lists/oss-security/2011/10/20/2
- http://www.redhat.com/support/errata/RHSA-2011-1401.html
- https://bugzilla.redhat.com/show_bug.cgi?id=736038
- https://github.com/bonzini/qemu/commit/103b40f51e4012b3b0ad20f615562a1806d7f49aExploitPatch
- https://github.com/bonzini/qemu/commit/7285477ab11831b1cf56e45878a89170dd06d9b9ExploitPatch
FAQ
What is CVE-2011-3346?
CVE-2011-3346 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest cr...
How severe is CVE-2011-3346?
CVE-2011-3346 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-3346?
Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Redhat Enterprise Linux, Xen Xen.