PT-2008-5771 · Fabrice Bellard+1 · Qemu+1
Jan Lieskovsky
·
Published
2008-12-29
·
Updated
2024-06-15
·
CVE-2008-4539
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
KVM versions prior to kvm-82
QEMU (affected versions not specified)
Description
A heap-based buffer overflow exists in the Cirrus VGA implementation, potentially allowing local users to gain privileges. This issue is related to an incorrect fix for a previous problem and might be exploited through the VNC console.
Recommendations
For KVM versions prior to kvm-82, update to version kvm-82 or later to resolve the issue.
For QEMU, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kvm
Qemu