UBUNTU-CVE-2013-4536
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-4536
UBUNTU-CVE-2013-4536
Summary:
Details: An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
References: https://ubuntu.com/security/CVE-2013-4536, http://lists.gnu.org/archive/html/qemu-devel/2013-12/msg00394.html, http://lists.gnu.org/archive/html/qemu-devel/2013-12/msg00408.html, https://ubuntu.com/security/notices/USN-2342-1, https://www.cve.org/CVERecord?id=CVE-2013-4536
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
