Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20140816013436.CE18BC502F1@smtptsrv1.mitre.org>
Date: Fri, 15 Aug 2014 21:34:36 -0400 (EDT)
From: cve-assign@...re.org
To: oss-security@...ts.openwall.com, aliguori@...zon.com, mst@...hat.com, amit.shah@...hat.com, lersek@...hat.com
Cc: cve-assign@...re.org
Subject: Re: CVE Request --  qemu: missing field list terminator in vmstate_xhci_event

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> It was found that vmstate_xhci_event field list was missing
> VMSTATE_END_OF_LIST() terminator and traversing through this list
> would result in out-of-bounds access
> 
> http://git.qemu.org/?p=qemu.git;a=commit;h=3afca1d6d413592c2b78cf28f52fa24a586d8f56
> https://bugzilla.redhat.com/show_bug.cgi?id=1126543

Use CVE-2014-5263.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJT7rS1AAoJEKllVAevmvms81IIAJStFbBq3fpNs3M/E3yijako
dlSiffBGimmv1s3oV41suqvE7WVv2zDRjfnRBAcRFFND5zj3Ga7hldP+59E2yeaG
5X25gnsxrJDhEbGFUHLM3hUi928czOWxH/L1TRN+Vq+HvWfkd6y2qNhPTgM8Q7lb
u92AqJwG0nI1PEjkES4Dnjv6OArHPDzTlNdVJJnizEV+Y7svYhHKb0xDnAT/DHAJ
xO2va5qP7ukpVGClXY7Cuj6YnhCJ1Wel4NLMN6G7gBntuml2SK60XHi/OqhxucjI
NWnRtZm9is9bqwsIlbvRF3qhZpWFXO7e8r4bHqigNQhIbQINbzGfTwhNNnkFTaQ=
=PmsW
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.