An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-28T16:58:49

Updated: 2024-08-06T16:45:14.837Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4536

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-28T17:15:07.350

Modified: 2024-11-21T01:55:47.040

Link: CVE-2013-4536

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-12-03T00:00:00Z

Links: CVE-2013-4536 - Bugzilla