QEMU "vmstate_xhci_event" Vulnerability
Release date:
Updated on:
Affected Systems:
QEMU 2.0.0
QEMU 1.7.2
Description:
--------------------------------------------------------------------------------
QEMU is an open source simulator software.
QEMU 1.7.2, 2.0.0 version of the "vmstate_xhci_event" structure (hw/usb/hcd-xhci.c) in the implementation of security vulnerabilities, successful exploitation can cause infinite loops or damage the QEMU process memory. To exploit this vulnerability, you can change the migration data.
<* Source: vendor
Link: http://secunia.com/advisories/59402/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.qemu.org /? P = qemu. git; a = commit; h = 3afca1d6d413592c2b78cf28f52fa24a586d8f56
Ubuntu 12.04 cannot find the Qemu command
Install QEMU + efi bios on Arch Linux
QEMU translation framework and debugging tools
QEMU details: click here
QEMU: click here
This article permanently updates the link address: