Integer overflow in the emulatedapdufrom_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12-ltss"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12-sp1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5898.json"