Vulnerability Name: | CVE-2011-2212 |
Assigned: | 2011-07-05 |
Published: | 2011-07-05 |
Updated: | 2023-02-13 |
Summary: | Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests." |
CVSS v3 Severity: | 7.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)Exploitability Metrics: | Attack Vector (AV): Adjacent Attack Complexity (AC): High Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 7.4 High (CVSS v2 Vector: AV:A/AC:M/Au:S/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Adjacent_Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 7.4 High (CCN CVSS v2 Vector: AV:A/AC:M/Au:S/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Adjacent_Network Access Complexity (AC): Medium Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 7.4 High (REDHAT CVSS v2 Vector: AV:A/AC:M/Au:S/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Adjacent_Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-119
|
References: | Source: MITRE Type: CNA CVE-2011-2212
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com
|
Vulnerable Configuration: | Configuration RedHat 1: cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*Configuration RedHat 2: cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |