vendor:
QEMU
by:
Unknown
7.5
CVSS
HIGH
Information Disclosure, Heap Overflow
Unknown
CWE
Product Name: QEMU
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Programmable Interrupt Timer (PIT) Controller in QEMU Information Disclosure and Heap Overflow
The programmable interrupt timer (PIT) controller in QEMU does not correctly validate the channel number when performing IO writes to the device controller, allowing both an information disclosure and heap-overflow within the context of the host. Depending on the layout of the data beyond the heap allocation, this vulnerability can set various bytes just beyond the heap allocation to non-attacker controlled values (mainly zero), as well as leaking various bytes from beyond the heap allocation back to the guest.
Mitigation:
Unknown