MEDIUM · 4.6

CVE-2014-0223

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, whic...

Vulnerability Description

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SuseLinux Enterprise Server11.0
QemuQemu<= 1.7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0223?

CVE-2014-0223 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, whic...

How severe is CVE-2014-0223?

CVE-2014-0223 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0223?

Check the references section above for vendor advisories and patch information. Affected products include: Suse Linux Enterprise Server, Qemu Qemu.