Release date:
Updated on:
Affected Systems:
QEMU
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66932
QEMU is an open source simulator software.
The qemu ide device module has an out-of-bounds memory access vulnerability. When executing the ide smart Command, a buffer overflow is triggered, resulting in QEMU memory corruption.
Ubuntu 12.04 cannot find the Qemu command
Install QEMU + efi bios on Arch Linux
QEMU translation framework and debugging tools
<* Source: Beno & #195; & #174; t Canet
Link: http://www.openwall.com/lists/oss-security/2014/04/15/4
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://fabrice.bellard.free.fr/qemu/
Https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02016.html
QEMU details: click here
QEMU: click here