Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3710

Опубликовано: 09 мая 2016
Источник: redhat
CVSS3: 7.6
CVSS2: 6.5
EPSS Низкий

Описание

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

An out-of-bounds read/write access flaw was found in the way QEMU's VGA emulation with VESA BIOS Extensions (VBE) support performed read/write operations using I/O port methods. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the host's QEMU process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmAffected
Red Hat Enterprise Linux 6qemu-kvm-rhevAffected
Red Hat Enterprise Linux 7qemu-kvm-rhevAffected
Red Hat OpenStack Platform 9 (Mitaka)qemu-kvm-rhevAffected
Red Hat Enterprise Linux 5kvmFixedRHSA-2016:194327.09.2016
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2016:099710.05.2016
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2016:072409.05.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6qemu-kvm-rhevFixedRHSA-2016:101911.05.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qemu-kvm-rhevFixedRHSA-2016:099910.05.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7qemu-kvm-rhevFixedRHSA-2016:100010.05.2016

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1331401qemu: incorrect banked access bounds checking in vga module

EPSS

Процентиль: 26%
0.00086
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
nvd
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
debian
больше 9 лет назад

The VGA module in QEMU improperly performs bounds checking on banked a ...

CVSS3: 8.8
github
больше 3 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

oracle-oval
больше 9 лет назад

ELSA-2016-0997: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 26%
0.00086
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS2