CVE-2011-3346
Last modified
CVE-2011-3346 is a vulnerability of currently unknown severity. Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Qemu | Qemu | <= 0.15.1 | — |
| Qemu | Qemu | 0.15.0 | Rc1 |
| Redhat | Enterprise Linux | 5 | — |
| Xen | Xen | All versions | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3346?
How severe is CVE-2011-3346?
How do I fix CVE-2011-3346?
Are you affected by CVE-2011-3346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
