Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49mx-v59p-m55m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

EPSS

Процентиль: 80%
0.01523
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

CVSS3: 5.5
redhat
больше 8 лет назад

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

CVSS3: 5.5
nvd
почти 7 лет назад

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

CVSS3: 5.5
debian
почти 7 лет назад

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA e ...

oracle-oval
около 8 лет назад

ELSA-2017-0987: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 80%
0.01523
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-119