Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3165

Опубликовано: 25 сент. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

An integer underflow issue was found in the QEMU built-in VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

Отчет

Red Hat Enterprise Linux 6, 7 and RHEL Advanced Virtualization are not affected by this flaw as they did not include support for the extended clipboard pseudo-encoding (upstream commit 0bf41cab).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmNot affected
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:275716.05.2023
Red Hat Enterprise Linux 9qemu-kvmFixedRHSA-2023:216209.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-191->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2129739QEMU: VNC: integer underflow in vnc_client_cut_text_ext leads to CPU exhaustion

EPSS

Процентиль: 27%
0.00092
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

CVSS3: 6.5
nvd
больше 2 лет назад

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

CVSS3: 6.5
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
больше 2 лет назад

An integer underflow issue was found in the QEMU VNC server while proc ...

CVSS3: 6.5
github
больше 2 лет назад

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

EPSS

Процентиль: 27%
0.00092
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2022-3165