CVE-2017-15289
Qemu: cirrus: OOB access issue in mode4and5 write functions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.
Las funciones de escritura mode4and5 en hw/display/cirrus_vga.c en Qemu permiten que usuarios del sistema operativo invitados con privilegios provoquen una denegación de servicio (acceso de lectura fuera de límites y cierre inesperado del proceso Qemu) mediante vectores relacionados con el cálculo dst.
Quick emulator (QEMU), compiled with the Cirrus CLGD 54xx VGA Emulator support, is vulnerable to an OOB write access issue. The issue could occur while writing to VGA memory via mode4and5 write functions. A privileged user inside guest could use this flaw to crash the QEMU process resulting in Denial of Serivce (DoS).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-12 CVE Reserved
- 2017-10-16 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101262 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/10/12/16 | 2020-11-10 | |
https://lists.gnu.org/archive/html/qemu-devel/2017-10/msg02557.html | 2020-11-10 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:3368 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3369 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3466 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3470 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3471 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3472 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3473 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2017:3474 | 2020-11-10 | |
https://access.redhat.com/errata/RHSA-2018:0516 | 2020-11-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1501290 | 2018-03-13 | |
https://usn.ubuntu.com/3575-1 | 2020-11-10 | |
https://www.debian.org/security/2018/dsa-4213 | 2020-11-10 | |
https://access.redhat.com/security/cve/CVE-2017-15289 | 2018-03-13 |