Bug 893323 - (CVE-2014-5388) VUL-1: CVE-2014-5388: qemu: out of bounds memory access
(CVE-2014-5388)
VUL-1: CVE-2014-5388: qemu: out of bounds memory access
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Bruce Rogers
Security Team bot
https://smash.suse.de/issue/105306/
CVSSv2:RedHat:CVE-2014-5388:2.9:(AV:A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-25 09:18 UTC by Alexander Bergmann
Modified: 2017-09-21 11:22 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-08-25 09:18:32 UTC
Via rh#1132956:

An out of bounds memory access flaw was found in Qemu's ACPI PCI hotplug
interface. It leads to Qemu's memory corruption via OOB write(4 bytes) and 
information disclosure(~12 bytes) through OOB read.

A user with a custom PCI device could use this flaw to leak qemu process'
memory bytes or corrupt them on the host.

Upstream fix:
-------------
  -> https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html

CVE-2014-5388 was assigned to this issue.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1132956
Comment 2 Swamp Workflow Management 2014-08-25 22:00:13 UTC
bugbot adjusting priority
Comment 5 Swamp Workflow Management 2016-11-12 07:07:37 UTC
SUSE-SU-2016:2781-1: An update that fixes 21 vulnerabilities is now available.

Category: security (moderate)
Bug References: 893323,944697,967012,967013,982017,982018,982019,982222,982223,982285,982959,983961,983982,991080,991466,994760,994771,994774,996441,997858,997859
CVE References: CVE-2014-5388,CVE-2015-6815,CVE-2016-2391,CVE-2016-2392,CVE-2016-4453,CVE-2016-4454,CVE-2016-5105,CVE-2016-5106,CVE-2016-5107,CVE-2016-5126,CVE-2016-5238,CVE-2016-5337,CVE-2016-5338,CVE-2016-5403,CVE-2016-6490,CVE-2016-6833,CVE-2016-6836,CVE-2016-6888,CVE-2016-7116,CVE-2016-7155,CVE-2016-7156
Sources used:
SUSE Linux Enterprise Server for SAP 12 (src):    qemu-2.0.2-48.22.1
SUSE Linux Enterprise Server 12-LTSS (src):    qemu-2.0.2-48.22.1
Comment 6 Johannes Segitz 2017-09-21 11:22:51 UTC
fixed