CVE-2017-7980

Published: 21 April 2017

Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.04 (Hirsute Hippo)
Released (1:2.8+dfsg-3ubuntu3)
Ubuntu 20.04 LTS (Focal Fossa)
Released (1:2.8+dfsg-3ubuntu3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1:2.8+dfsg-3ubuntu3)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1:2.5+dfsg-5ubuntu10.14)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.0.0+dfsg-2ubuntu1.34)
Patches:
Upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=026aeffcb4752054830ba203020ed6eb05bcaba8
Upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=ffaf857778286ca54e3804432a2369a279e73aa7
Upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=f019722cbbb45aea153294fc8921fcc96a4d3fa2
qemu-kvm
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 21.04 (Hirsute Hippo) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist