CVE-2017-2615
Published: 1 February 2017
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
Notes
Author | Note |
---|---|
seth-arnold | apparently introduced by the fix for CVE-2014-8106 |
Priority
Status
Package | Release | Status |
---|---|---|
qemu Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
bionic |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
cosmic |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
disco |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
eoan |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
focal |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
groovy |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
hirsute |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
precise |
Does not exist
|
|
trusty |
Released
(2.0.0+dfsg-2ubuntu1.33)
|
|
upstream |
Needed
|
|
xenial |
Released
(1:2.5+dfsg-5ubuntu10.11)
|
|
yakkety |
Released
(1:2.6.1+dfsg-0ubuntu5.4)
|
|
zesty |
Not vulnerable
(1:2.8+dfsg-3ubuntu2)
|
|
Patches: upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=62d4c6bd5263bb8413a06c80144fc678df6dfb64 |
||
qemu-kvm Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
precise |
Ignored
(reached end-of-life)
|
|
trusty |
Does not exist
|
|
upstream |
Needed
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
xen Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(uses system qemu)
|
bionic |
Not vulnerable
(uses system qemu)
|
|
cosmic |
Not vulnerable
(uses system qemu)
|
|
disco |
Not vulnerable
(uses system qemu)
|
|
eoan |
Not vulnerable
(uses system qemu)
|
|
focal |
Not vulnerable
(uses system qemu)
|
|
groovy |
Not vulnerable
(uses system qemu)
|
|
hirsute |
Not vulnerable
(uses system qemu)
|
|
precise |
Ignored
(reached end-of-life)
|
|
trusty |
Released
(4.4.2-0ubuntu0.14.04.11)
|
|
upstream |
Needed
|
|
xenial |
Not vulnerable
(uses system qemu)
|
|
yakkety |
Not vulnerable
(uses system qemu)
|
|
zesty |
Not vulnerable
(uses system qemu)
|
|
Binaries built from this source package are in Universe and so are supported by the community. |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.1 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | High |
User interaction | None |
Scope | Changed |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |