CVE-2011-4111
EPSS 2.7%Published: 2/26/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2011-4111
Description
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
Affected packages (2)
- Debian/qemufrom 0, < 0.15.1+dfsg-2
- Debian/xenfrom 0, < 4.4.0-1