HIGH · 8.6

CVE-2014-0144

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input val...

Vulnerability Description

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QemuQemu< 2.0.0
RedhatVirtualization3.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.5
RedhatEnterprise Linux Openstack Platform5
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.5
RedhatEnterprise Linux Server Tus6.5
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0144?

CVE-2014-0144 is a vulnerability with a CVSS score of 8.6 (HIGH). QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input val...

How severe is CVE-2014-0144?

CVE-2014-0144 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0144?

Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Redhat Virtualization, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Openstack Platform.