CVE-2011-4111

QEMU <0.15.2, <1.0-rc4 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

References (5)

Core 5
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=751310
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1777.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2011-1801.html

Scores

EPSS 0.0267
EPSS Percentile 86.0%

Details

CWE
CWE-119
Status published
Products (5)
qemu/qemu 0.15.0 (3 CPE variants)
qemu/qemu 1.0 (4 CPE variants)
qemu/qemu < 0.15.1
redhat/enterprise_linux 6.0
redhat/enterprise_linux_server_supplementary 6.1.z
Published Feb 26, 2014
Tracked Since Feb 18, 2026