Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-2615

Опубликовано: 03 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9
CVSS3: 5.5

Описание

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

РелизСтатусПримечание
artful

not-affected

1:2.8+dfsg-3ubuntu2
bionic

not-affected

1:2.8+dfsg-3ubuntu2
cosmic

not-affected

1:2.8+dfsg-3ubuntu2
devel

not-affected

1:2.8+dfsg-3ubuntu2
disco

not-affected

1:2.8+dfsg-3ubuntu2
eoan

not-affected

1:2.8+dfsg-3ubuntu2
esm-infra-legacy/trusty

released

2.0.0+dfsg-2ubuntu1.33
esm-infra/bionic

not-affected

1:2.8+dfsg-3ubuntu2
esm-infra/focal

not-affected

1:2.8+dfsg-3ubuntu2
esm-infra/xenial

released

1:2.5+dfsg-5ubuntu10.11

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

uses system qemu
bionic

not-affected

uses system qemu
cosmic

not-affected

uses system qemu
devel

not-affected

uses system qemu
disco

not-affected

uses system qemu
eoan

not-affected

uses system qemu
esm-apps/focal

not-affected

uses system qemu
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [4.4.2-0ubuntu0.14.04.11]]
esm-infra/bionic

not-affected

uses system qemu
esm-infra/xenial

not-affected

uses system qemu

Показывать по

EPSS

Процентиль: 59%
0.00386
Низкий

9 Critical

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 9 лет назад

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

CVSS3: 5.5
nvd
больше 7 лет назад

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

CVSS3: 5.5
debian
больше 7 лет назад

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator sup ...

CVSS3: 9.1
github
больше 3 лет назад

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

oracle-oval
больше 8 лет назад

ELSA-2017-0454: kvm security update (IMPORTANT)

EPSS

Процентиль: 59%
0.00386
Низкий

9 Critical

CVSS2

5.5 Medium

CVSS3

Уязвимость CVE-2017-2615