CVE-2012-0029
xen-qemu-dm-4.0 - buffer overflow
EPSS 0.92%
描述
Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.
如何修補 CVE-2012-0029
要修補 CVE-2012-0029,請將受影響套件升級到下列已修補版本。
- Debian/qemu-kvm—升級至 0.12.5+dfsg-5+squeeze8 或更新版本
- Debian/xen—升級至 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 或更新版本
- Debian/xen-qemu-dm-4.0—升級至 4.0.1-2+squeeze1 或更新版本
CVE-2012-0029 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 0.12.5+dfsg-5+squeeze8
- from 0, < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1
- from 0, < 4.0.1-2+squeeze1