Описание
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1:2.8+dfsg-3ubuntu2.1 |
esm-infra-legacy/trusty | not-affected | 2.0.0+dfsg-2ubuntu1.33 |
esm-infra/xenial | not-affected | 1:2.5+dfsg-5ubuntu10.11 |
precise | DNE | |
precise/esm | DNE | |
trusty | released | 2.0.0+dfsg-2ubuntu1.33 |
trusty/esm | not-affected | 2.0.0+dfsg-2ubuntu1.33 |
upstream | needs-triage | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | not-affected | code not present |
precise/esm | not-affected | code not present |
trusty | DNE | |
trusty/esm | DNE | |
upstream | needs-triage | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | uses system qemu |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [4.4.2-0ubuntu0.14.04.11]] |
esm-infra/xenial | not-affected | uses system qemu |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
trusty | released | 4.4.2-0ubuntu0.14.04.11 |
trusty/esm | DNE | trusty was released [4.4.2-0ubuntu0.14.04.11] |
upstream | needed | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE |
Показывать по
EPSS
9 Critical
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA e ...
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
EPSS
9 Critical
CVSS2
5.5 Medium
CVSS3