[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2017-0396 -- Oracle qemu-kvm

ID: oval:org.secpod.oval:def:1501789Date: (C)2017-03-03   (M)2023-12-20
Class: PATCHFamily: unix




Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host. (CVE-2017-2615). Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process. (CVE-2017-2620)

Platform:
Oracle Linux 7
Product:
qemu-kvm
Reference:
ELSA-2017-0396
CVE-2017-2620
CVE-2017-2615
CVE    2
CVE-2017-2620
CVE-2017-2615
CPE    2
cpe:/a:kvm_group:qemu-kvm
cpe:/o:oracle:linux:7

© SecPod Technologies