Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2014-0222

Disclosure Date: November 04, 2014
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

An integer overflow flaw was found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use this flaw to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

General Information

Vendors

  • Red Hat

Products

  • OpenStack 4 for RHEL 6,
  • Red Hat Enterprise Linux 6,
  • Red Hat Enterprise Linux 7,
  • Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6,
  • Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7,
  • RHEV 3.X Hypervisor and Agents for RHEL-6
Technical Analysis