Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3615

Опубликовано: 05 сент. 2014
Источник: redhat
CVSS2: 2.9

Описание

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

An information leak flaw was found in the way QEMU's VGA emulator accessed frame buffer memory for high resolution displays. A privileged guest user could use this flaw to leak memory contents of the host to the guest by setting the display to use a high resolution in the guest.

Отчет

This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5 or the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6qemu-kvm-rhevNot affected
Red Hat OpenStack Platform 4qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2014:166920.10.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qemu-kvm-rhevFixedRHSA-2014:194102.12.2014
RHEV 3.X Hypervisor and Agents for RHEL-7qemu-kvm-rhevFixedRHSA-2014:167020.10.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1139115Qemu: information leakage when guest sets high resolution

2.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

nvd
больше 11 лет назад

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

debian
больше 11 лет назад

The VGA emulator in QEMU allows local guest users to read host memory ...

github
больше 3 лет назад

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

oracle-oval
больше 11 лет назад

ELSA-2014-1669: qemu-kvm security and bug fix update (LOW)

2.9 Low

CVSS2