Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6gr-ph59-9hqm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

EPSS

Процентиль: 73%
0.00774
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

CVSS3: 5.5
redhat
больше 8 лет назад

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

CVSS3: 5.5
nvd
больше 7 лет назад

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

CVSS3: 5.5
debian
больше 7 лет назад

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA E ...

oracle-oval
больше 8 лет назад

ELSA-2017-0352: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 73%
0.00774
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-125