QEMU local DoS Vulnerability (CVE-2014-3640)
Release date:
Updated on:
Affected Systems:
QEMU 2.x
Description:
Bugtraq id: 70237
CVE (CAN) ID: CVE-2014-3640
QEMU is an open source simulator software.
In versions earlier than QEMU 2.1.2, a null pointer indirect reference error exists in the udp_input () function (slirp/udp. c). This vulnerability can be exploited by local users to cause a crash. This vulnerability only affects clients that use the QEMU user network.
<* Source: Xavier Mehrenberger
*>
Suggestion:
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://lists.gnu.org/archive/html/qemu-stable/2014-09/msg00231.html
Https://lists.gnu.org/archive/html/qemu-stable/2014-09/msg00269.html
Ubuntu 12.04 cannot find the Qemu command
Install QEMU + efi bios on Arch Linux
QEMU translation framework and debugging tools
QEMU details: click here
QEMU: click here
This article permanently updates the link address: