PT-2023-9176 · Qemu+10 · Qemu+10

Mauro Matteo Cascella

·

Published

2023-07-04

·

Updated

2025-01-28

·

CVE-2023-3255

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker-controlled zlib buffer in the inflate buffer function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALSA-2024:2135
ALT-PU-2023-5106
ALT-PU-2023-5241
ALT-PU-2023-7183
ALT-PU-2024-1248
ALT-PU-2024-13687
ALT-PU-2024-14149
ALT-PU-2024-6235
ALT-PU-2024-7201
AZL-28791
AZL-35169
BDU:2024-04419
CESA-2024_2962
CVE-2023-3255
INFSA-2024_2135
INFSA-2024_2962
MGASA-2024-0387
OESA-2023-1785
OESA-2023-1786
OESA-2023-1787
OPENSUSE-SU-2023_3082-1
OPENSUSE-SU-2023_3234-1
OPENSUSE-SU-2024:13082-1
RHSA-2024:2135
RHSA-2024:2962
RHSA-2024_2135
RHSA-2024_2962
RLSA-2024:2135
RLSA-2024:2962
ROSA-SA-2025-2641
SUSE-SU-2023:3082-1
SUSE-SU-2023:3082-2
SUSE-SU-2023:3234-1
SUSE-SU-2023_3082-1
USN-6567-1
USN-6567-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu