CVE-2014-0142

Publication date 26 March 2014

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.5 · Medium

Score breakdown

Description

QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.

Status

Package Ubuntu Release Status
qemu 14.04 LTS trusty
Not affected
13.10 saucy Ignored end of life
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
qemu-kvm 14.04 LTS trusty Not in release
13.10 saucy Not in release
12.10 quantal Ignored end of life
12.04 LTS precise
Fixed 1.0+noroms-0ubuntu14.17
10.04 LTS lucid
Fixed 0.12.3+noroms-0ubuntu9.24

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.5 · Medium

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-2342-1
    • QEMU vulnerabilities
    • 8 September 2014

Other references


Access our resources on patching vulnerabilities