Out-of-Bounds Array Access in virtio_scsi_load_request Function in QEMU

Out-of-Bounds Array Access in virtio_scsi_load_request Function in QEMU

CVE-2013-4542 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.

Learn more about our Web Application Penetration Testing UK.