Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-13672

Опубликовано: 24 авг. 2017
Источник: redhat
CVSS3: 3
CVSS2: 2.3
EPSS Низкий

Описание

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

An out-of-bounds read access issue was found in the VGA display emulator built into the Quick emulator (QEMU). It could occur while reading VGA memory to update graphics display. A privileged user/process inside guest could use this flaw to crash the QEMU process on the host resulting in denial of service situation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 5xenWill not fix
Red Hat Enterprise Linux 6qemu-kvm-rhevAffected
Red Hat Enterprise Linux 7qemu-kvm-rhevAffected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)qemu-kvm-rhevWill not fix
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2018:216210.07.2018
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2018:081610.04.2018
Red Hat OpenStack Platform 10.0 (Newton)qemu-kvm-rhevFixedRHSA-2018:111311.04.2018
Red Hat OpenStack Platform 11.0 (Ocata)qemu-kvm-rhevFixedRHSA-2018:111311.04.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1486560QEMU: vga: OOB read access during display update

EPSS

Процентиль: 67%
0.00564
Низкий

3 Low

CVSS3

2.3 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

CVSS3: 5.5
nvd
почти 8 лет назад

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

CVSS3: 5.5
debian
почти 8 лет назад

QEMU (aka Quick Emulator), when built with the VGA display emulator su ...

CVSS3: 5.5
github
около 3 лет назад

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

oracle-oval
почти 7 лет назад

ELSA-2018-2162: qemu-kvm security update (IMPORTANT)

EPSS

Процентиль: 67%
0.00564
Низкий

3 Low

CVSS3

2.3 Low

CVSS2

Уязвимость CVE-2017-13672