Out-of-bounds Read Affecting qemu package, versions <2.1+dfsg-1
Snyk CVSS
Attack Complexity
Low
Availability
High
Threat Intelligence
EPSS
0.24% (62nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-QEMU-427283
- published 27 Jun 2018
- disclosed 27 Jul 2018
How to fix?
Upgrade Debian:unstable
qemu
to version 2.1+dfsg-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream qemu
package and not the qemu
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
References
- https://security-tracker.debian.org/tracker/CVE-2017-2633
- https://git.qemu.org/?p=qemu.git;a=commitdiff;h=9f64916da20eea67121d544698676295bbb105a7
- https://git.qemu.org/?p=qemu.git;a=commitdiff;h=bea60dd7679364493a0d7f5b54316c767cf894ef
- http://www.openwall.com/lists/oss-security/2017/02/23/1
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633
- https://access.redhat.com/errata/RHSA-2017:1205
- https://access.redhat.com/errata/RHSA-2017:1206
- https://access.redhat.com/errata/RHSA-2017:1441
- https://access.redhat.com/errata/RHSA-2017:1856
- http://www.securityfocus.com/bid/96417
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2017-2633
- https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7
- https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894ef