Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3712

Опубликовано: 11 мая 2016
Источник: debian

Описание

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.6+dfsg-1package
qemu-kvmremovedpackage
xenfixed4.4.0-1package
xenno-dsawheezypackage

Примечания

  • Xen switched to qemu-system in 4.4.0-1

  • http://xenbits.xen.org/xsa/advisory-179.html

  • mitigation: run HVM in stubdomains, PV, default video card not vulnerable, i386-only

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 10 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

redhat
около 10 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
nvd
около 10 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
github
около 4 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

oracle-oval
больше 9 лет назад

ELSA-2017-0621: qemu-kvm security and bug fix update (MODERATE)