{"id":"CVE-2014-0146","details":"The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.","modified":"2026-04-16T06:16:22.390663554Z","published":"2017-08-10T15:29:00Z","related":["SUSE-SU-2015:0870-1","SUSE-SU-2015:0889-1","SUSE-SU-2015:1152-1","openSUSE-SU-2024:10233-1"],"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0420.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0421.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-3044"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2014/03/26/8"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1078232"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2014/03/26/8"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1078232"},{"type":"WEB","url":"http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=11b128f4062dd7f89b14abc8877ff20d41b28be9"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}