Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3710

Опубликовано: 11 мая 2016
Источник: debian
EPSS Низкий

Описание

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.6+dfsg-1package
qemu-kvmremovedpackage
xenfixed4.4.0-1package
xenno-dsawheezypackage

Примечания

  • Xen switched to qemu-system in 4.4.0-1

  • http://xenbits.xen.org/xsa/advisory-179.html

  • mitigation: run HVM in stubdomains, PV, default video card not vulnerable, i386-only

EPSS

Процентиль: 26%
0.00086
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 7.6
redhat
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
nvd
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
github
больше 3 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

oracle-oval
больше 9 лет назад

ELSA-2016-0997: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 26%
0.00086
Низкий