Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6683

Опубликовано: 12 янв. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:8.2.0+ds-5package
qemufixed1:7.2+dfsg-7+deb12u4bookwormpackage
qemunot-affectedbullseyepackage
qemunot-affectedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2254825

  • Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/660e8d0f0be4e87da937ce797973874bb282d498 (v6.1.0-rc0)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/405484b29f6548c7b86549b0f961b906337aa68a

EPSS

Процентиль: 29%
0.00102
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

CVSS3: 6.5
redhat
больше 1 года назад

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

CVSS3: 6.5
nvd
больше 1 года назад

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

CVSS3: 6.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 6.5
github
больше 1 года назад

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

EPSS

Процентиль: 29%
0.00102
Низкий