2.3
CVSSv2

CVE-2013-4377

Published: 11/10/2013 Updated: 06/03/2014
CVSS v2 Base Score: 2.3 | Impact Score: 2.9 | Exploitability Score: 4.4
VMScore: 205
Vector: AV:A/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 up to and including 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 1.5.1

qemu qemu 1.5.2

qemu qemu 1.4.0

qemu qemu 1.4.2

qemu qemu 1.5.3

qemu qemu 1.6.0

qemu qemu 1.5.0

qemu qemu 1.4.1

Vendor Advisories

Several security issues were fixed in QEMU ...
Use-after-free vulnerability in the virtio-pci implementation in Qemu 140 through 160 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device ...