CVE-2011-4111
EPSS 2.7%
Description
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
How to fix CVE-2011-4111
To remediate CVE-2011-4111, upgrade the affected package to a fixed version below.
- Debian/qemu—upgrade to 0.15.1+dfsg-2 or later
- Debian/xen—upgrade to 4.4.0-1 or later
Is CVE-2011-4111 being exploited?
Low — EPSS is 2.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.15.1+dfsg-2
- from 0, < 4.4.0-1