4.7
CVSSv2

CVE-2008-0928

Published: 03/03/2008 Updated: 02/11/2020
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

Qemu 0.9.1 and previous versions does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.1.4

qemu qemu 0.1.5

qemu qemu 0.4.3

qemu qemu 0.5.0

qemu qemu 0.6.1

qemu qemu 0.7.0

qemu qemu 0.1.6

qemu qemu 0.2.0

qemu qemu 0.5.1

qemu qemu 0.5.2

qemu qemu 0.7.1

qemu qemu 0.7.2

qemu qemu 0.8.0

qemu qemu 0.1.2

qemu qemu 0.1.3

qemu qemu 0.4.1

qemu qemu 0.4.2

qemu qemu 0.5.5

qemu qemu 0.6.0

qemu qemu 0.9.0

qemu qemu 0.9.1

qemu qemu 0.1.0

qemu qemu 0.1.1

qemu qemu 0.3.0

qemu qemu 0.4.0

qemu qemu 0.5.3

qemu qemu 0.5.4

qemu qemu 0.8.1

qemu qemu 0.8.2

Vendor Advisories

Debian Bug report logs - #526040 qemu: CVE-2008-4539 buffer overlflow vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 ...
Debian Bug report logs - #469649 qemu: CVE-2008-0928 privilege escalation Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 6 Mar 2008 11:18:04 UTC Severity: importan ...
Debian Bug report logs - #526013 qemu: CVE-2008-1945 media handling vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 17 ...