CVE Vulnerabilities

CVE-2014-5388

Off-by-one Error

Published: Nov 15, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
2.9 LOW
AV:A/AC:H/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 2.1.3 (including)
Qemu Ubuntu devel *
Qemu Ubuntu trusty *
Qemu Ubuntu utopic *

Potential Mitigations

References