Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3712

Опубликовано: 09 мая 2016
Источник: redhat
CVSS2: 3.8
EPSS Низкий

Описание

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

An integer overflow flaw and an out-of-bounds read flaw were found in the way QEMU's VGA emulator set certain VGA registers while in VBE mode. A privileged guest user could use this flaw to crash the QEMU process instance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 5xenWill not fix
Red Hat Enterprise Linux 6qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux 7qemu-kvm-rhevAffected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)qemu-kvm-rhevWill not fix
Red Hat OpenStack Platform 8 (Liberty)qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2017:062121.03.2017
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2016:258503.11.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1318712qemu-kvm: Out-of-bounds read when creating weird vga screen surface

EPSS

Процентиль: 31%
0.00116
Низкий

3.8 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
nvd
больше 9 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
debian
больше 9 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users ...

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

oracle-oval
больше 8 лет назад

ELSA-2017-0621: qemu-kvm security and bug fix update (MODERATE)

EPSS

Процентиль: 31%
0.00116
Низкий

3.8 Low

CVSS2

Уязвимость CVE-2016-3712