PT-2017-15453 · Qemu+5 · Qemu+5

Gerd Hoffmann

·

Publicado

2017-01-17

·

Atualizado

2024-06-15

·

CVE-2017-2620

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.8
Description The issue is related to an out-of-bounds access problem that could occur while copying VGA data in the cirrus bitblt cputovideo function. A privileged user inside the guest could potentially use this flaw to crash the QEMU process or execute arbitrary code on the host with the privileges of the QEMU process.
Recommendations For QEMU versions prior to 2.8, update to version 2.8 or later to resolve the issue.

Exploit

Correção

Out of bounds Read

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1043
CESA-2017_0352
CESA-2017_0396
CVE-2017-2620
DLA-1270-1
DLA-1497-1
DLA-842-1
DLA-845-1
OPENSUSE-SU-2017_0665-1
OPENSUSE-SU-2017_0707-1
OPENSUSE-SU-2024:11287-1
OPENSUSE-SU-2024:11520-1
RHSA-2017:0328
RHSA-2017:0329
RHSA-2017:0330
RHSA-2017:0331
RHSA-2017:0332
RHSA-2017:0333
RHSA-2017:0334
RHSA-2017:0350
RHSA-2017:0351
RHSA-2017:0352
RHSA-2017:0396
RHSA-2017:0454
RHSA-2017_0352
RHSA-2017_0396
RHSA-2017_0454
SUSE-SU-2017:0570-1
SUSE-SU-2017:0571-1
SUSE-SU-2017:0582-1
SUSE-SU-2017:0625-1
SUSE-SU-2017:0647-1
SUSE-SU-2017:0661-1
SUSE-SU-2017:0718-1
SUSE-SU-2017:1135-1
SUSE-SU-2017:1241-1
SUSE-SU-2017:3084-1
USN-3261-1

Produtos afetados

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu