#VU13375 Heap-based buffer overflow in QEMU - CVE-2018-11806
Published: June 16, 2018 / Updated: June 18, 2018
QEMU
QEMU
Description
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists due to heap-based buffer overflow when insufficient input and validation checking of Slirp networking back-end processes by the m_cat function, as defined in the slirp/mbuf.c source code file. A remote attacker can send malformed, fragmented packets, trigger memory corruption and cause the QEMU process to crash.