Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15124

Опубликовано: 09 янв. 2018
Источник: debian
EPSS Низкий

Описание

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.12~rc3+dfsg-1package
qemuignoredjessiepackage
qemupostponedwheezypackage
qemu-kvmremovedpackage
qemu-kvmpostponedwheezypackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/12/19/4

  • https://lists.gnu.org/archive/html/qemu-devel/2017-12/msg03705.html

  • https://lists.gnu.org/archive/html/qemu-devel/2018-02/msg00796.html

EPSS

Процентиль: 73%
0.008
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

CVSS3: 3.5
redhat
больше 7 лет назад

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

CVSS3: 7.5
nvd
больше 7 лет назад

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

CVSS3: 7.5
github
около 3 лет назад

VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость реализации VNC-сервера эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 73%
0.008
Низкий