Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3247

Опубликовано: 03 сент. 2015
Источник: redhat
CVSS2: 7.7
EPSS Низкий

Описание

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

A race condition flaw, leading to a heap-based memory corruption, was found in spice's worker_update_monitors_config() function, which runs under the QEMU-KVM context on the host. A user in a guest could leverage this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process.

Дополнительная информация

Статус:

Important
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1233238spice: memory corruption in worker_update_monitors_config()

EPSS

Процентиль: 73%
0.00771
Низкий

7.7 High

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

nvd
почти 10 лет назад

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

debian
почти 10 лет назад

Race condition in the worker_update_monitors_config function in SPICE ...

github
больше 3 лет назад

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

oracle-oval
почти 10 лет назад

ELSA-2015-1715: spice-server security update (IMPORTANT)

EPSS

Процентиль: 73%
0.00771
Низкий

7.7 High

CVSS2