PT-2016-5672 · Qemu+5 · Qemu+5

P J P

+1

·

Published

2016-05-09

·

Updated

2024-06-15

·

CVE-2016-3712

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is related to an integer overflow in the VGA module, allowing local guest OS users to cause a denial of service. This can be achieved by editing VGA registers in VBE mode, resulting in an out-of-bounds read and a crash of the QEMU process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1565
CESA-2016_2585
CESA-2017_0621
CVE-2016-3712
DLA-539-1
DLA-540-1
DLA-571-1
DSA-3573-1
MGASA-2016-0176
MGASA-2017-0012
OPENSUSE-SU-2016_1750-1
OPENSUSE-SU-2016_2494-1
OPENSUSE-SU-2016_2497-1
OPENSUSE-SU-2024:10233-1
OPENSUSE-SU-2024:10285-1
RHSA-2016:2585
RHSA-2016_2585
RHSA-2017:0621
RHSA-2017_0621
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1703-1
SUSE-SU-2016:1785-1
SUSE-SU-2016:2533-1
SUSE-SU-2016:2725-1
USN-2974-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu