CVE-2017-2633
CVE-2017-2633
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Affected products
QEMU · Qemu:Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://access.redhat.com/errata/RHSA-2017:1205https://access.redhat.com/errata/RHSA-2017:1206https://access.redhat.com/errata/RHSA-2017:1441https://access.redhat.com/errata/RHSA-2017:1856https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894efhttp://www.openwall.com/lists/oss-security/2017/02/23/1http://www.securityfocus.com/bid/96417