PT-2017-18886 · Qemu+3 · Qemu+3

Publicado

2017-04-25

·

Atualizado

2020-11-10

·

CVE-2017-9375

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (aka Quick Emulator) versions (affected versions not specified)
Description The issue allows local guest OS privileged users to cause a denial of service, specifically an infinite recursive call. This can be achieved through vectors involving control transfer descriptors sequencing when QEMU is built with USB xHCI controller emulator support.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1521
CVE-2017-9375
DLA-1927-1
DSA-3920-1
DSA-3991-1
OPENSUSE-SU-2017_1872-1
RHSA-2017:2392
RHSA-2017:2408
SUSE-SU-2017:1774-1
SUSE-SU-2017:2946-1
SUSE-SU-2017:2963-1
SUSE-SU-2017:2969-1
SUSE-SU-2017:3084-1
USN-3414-1
USN-3414-2

Produtos afetados

Alt Linux
Qemu
Suse
Ubuntu