Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15289

Опубликовано: 11 окт. 2017
Источник: redhat
CVSS3: 4.4
CVSS2: 2.9
EPSS Низкий

Описание

The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.

Quick emulator (QEMU), compiled with the Cirrus CLGD 54xx VGA Emulator support, is vulnerable to an OOB write access issue. The issue could occur while writing to VGA memory via mode4and5 write functions. A privileged user inside guest could use this flaw to crash the QEMU process resulting in Denial of Serivce (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 5xenWill not fix
Red Hat OpenStack Platform 12 (Pike)qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2018:051613.03.2018
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2017:336830.11.2017
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7qemu-kvm-rhevFixedRHSA-2017:347314.12.2017
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7qemu-kvm-rhevFixedRHSA-2017:347214.12.2017
Red Hat OpenStack Platform 10.0 (Newton)qemu-kvm-rhevFixedRHSA-2017:347414.12.2017
Red Hat OpenStack Platform 11.0 (Ocata)qemu-kvm-rhevFixedRHSA-2017:346614.12.2017
Red Hat OpenStack Platform 8.0 (Liberty)qemu-kvm-rhevFixedRHSA-2017:347114.12.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1501290Qemu: cirrus: OOB access issue in mode4and5 write functions

EPSS

Процентиль: 26%
0.00089
Низкий

4.4 Medium

CVSS3

2.9 Low

CVSS2

Связанные уязвимости

CVSS3: 6
ubuntu
почти 8 лет назад

The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.

CVSS3: 6
nvd
почти 8 лет назад

The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.

CVSS3: 6
debian
почти 8 лет назад

The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow ...

CVSS3: 6
github
около 3 лет назад

The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.

oracle-oval
больше 7 лет назад

ELSA-2018-0516: qemu-kvm security update (MODERATE)

EPSS

Процентиль: 26%
0.00089
Низкий

4.4 Medium

CVSS3

2.9 Low

CVSS2