CVE-2008-4539
published 2008-12-29CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.54%
42.0th percentile
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 0.9.1+svn20081101-1 (bookworm) | qemu 0.9.1+svn20081101-1 (bookworm) |
| kvm_qumranet | kvm | <= 81 | — |
| qemu | qemu | < 0.10.0 | 0.10.0 |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq7c-3rjh-ggvh: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
ghsa_unreviewed·2022-05-02·CVSS 7.2
CVE-2008-4539 [HIGH] CWE-119 GHSA-gq7c-3rjh-ggvh: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
OSV
CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
osv·2008-12-29·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Ubuntu
KVM regression
vendor_ubuntu·2009-05-13·CVSS 2.1
[LOW] KVM regression
Title: KVM regression
Summary: KVM regression
USN-776-1 fixed vulnerabilities in KVM. Due to an incorrect fix, a
regression was introduced in Ubuntu 8.04 LTS that caused KVM to fail to
boot virtual machines started via libvirt. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Avi Kivity discovered that KVM did not correctly handle certain disk
formats. A local attacker could attach a malicious partition that would
allow the guest VM to read files on the VM host. (CVE-2008-1945,
CVE-2008-2004)
Alfredo Ortega discovered that KVM's VNC protocol handler did not
correctly validate certain messages. A remote attacker could send
specially crafted VNC messages that would cause KVM to consume CPU
resources, leading to a denial of service. (CVE-2008-
Ubuntu
KVM vulnerabilities
vendor_ubuntu·2009-05-12·CVSS 2.1
CVE-2008-1945 [LOW] KVM vulnerabilities
Title: KVM vulnerabilities
Summary: KVM vulnerabilities
Avi Kivity discovered that KVM did not correctly handle certain disk
formats. A local attacker could attach a malicious partition that
would allow the guest VM to read files on the VM host. (CVE-2008-1945,
CVE-2008-2004)
Alfredo Ortega discovered that KVM's VNC protocol handler did not
correctly validate certain messages. A remote attacker could send
specially crafted VNC messages that would cause KVM to consume CPU
resources, leading to a denial of service. (CVE-2008-2382)
Jan Niehusmann discovered that KVM's Cirrus VGA implementation over VNC
did not correctly handle certain bitblt operations. A local attacker
could exploit this flaw to potentially execute arbitrary code on the VM
host or crash KVM, leading to a denial of servic
Red Hat
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
vendor_redhat·2008-10-29·CVSS 7.2
CVE-2008-4539 [HIGH] kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Debian
CVE-2008-4539: qemu - Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kv...
vendor_debian·2008·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539: qemu - Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kv...
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Scope: local
bookworm: resolved (fixed in 0.9.1+svn20081101-1)
bullseye: resolved (fixed in 0.9.1+svn20081101-1)
forky: resolved (fixed in 0.9.1+svn20081101-1)
sid: resolved (fixed in 0.9.1+svn20081101-1)
trixie: resolved (fixed in 0.9.1+svn20081101-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
bugzilla·2008-10-14·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Created attachment 320281
Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)
Jan Niehusmann discovered that the upstream fix for the CVE-2007-1320 is
incomplete and still allows local users to cause a heap-based buffer overlow,
when connecting via the VNC console.
Steps to reproduce:
No reproducer.
Upstream qemu patch for the initial CVE-2007-1320 issue:
https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch
Proposed upstream correction of this patch - see attachment.
Discussion:
QEMU upstream commit:
http://git.kernel.dk/?p=qemu.git;a=commitdiff;h=65d35a09979e63541afc5bfc595b9f1b1b4ae069
More on current status of thi
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
kvm-60-6.fc8 has been submitted as an update for Fedora 8
Discussion:
*** This bug has been marked as a duplicate of 237342 ***
---
kvm-60-6.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-60-7.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/kvm-60-7.fc8
---
kvm-60-7.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
kvm-65-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Discussion:
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-65-11.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/kvm-65-11.fc9
---
kvm-65-11.fc9 has been pushed to the Fedora 9 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update kvm'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-9571
---
kvm-65-13.fc9 has been subm
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
bugzilla·2007-04-20·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
The cirrus_invalidate_region() routine used during video-to-video copy
operations in the cirrus vga extension code omits bounds checking in
multiple locations, allowing you to overwrite adjacent buffers by
attempting to mark non-existent regions as dirty. Successful
exploitation would result in a complete compromise of the qemu
process. Additionally multiple bitblt operations omit bounds checking,
where the srcpitch or dstpitch coefficients cause the operation to
exceed the bounds of the vram buffer.
Discussion:
Upstream applied this fix:
http://xenbits.xensource.com/xen-unstable.hg?rev/9e86260b95a4
---
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release.
http://git.kernel.dk/?p=qemu.git%3Ba=commitdiff%3Bh=65d35a09979e63541afc5bfc595b9f1b1b4ae069http://groups.google.com/group/linux.debian.changes.devel/msg/9e0dc008572f2867?dmode=sourcehttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/25073http://secunia.com/advisories/29129http://secunia.com/advisories/33350http://secunia.com/advisories/34642http://secunia.com/advisories/35031http://secunia.com/advisories/35062http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5587http://www.debian.org/security/2009/dsa-1799http://www.mail-archive.com/cvs-all%40freebsd.org/msg129730.htmlhttp://www.mail-archive.com/secure-testing-commits%40lists.alioth.debian.org/msg09322.htmlhttp://www.ubuntu.com/usn/usn-776-1https://bugzilla.redhat.com/show_bug.cgi?id=237342https://bugzilla.redhat.com/show_bug.cgi?id=448525https://bugzilla.redhat.com/show_bug.cgi?id=466890https://exchange.xforce.ibmcloud.com/vulnerabilities/47736https://launchpad.net/ubuntu/jaunty/+source/qemu/0.9.1+svn20081112-1ubuntu1https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01223.htmlhttp://git.kernel.dk/?p=qemu.git%3Ba=commitdiff%3Bh=65d35a09979e63541afc5bfc595b9f1b1b4ae069http://groups.google.com/group/linux.debian.changes.devel/msg/9e0dc008572f2867?dmode=sourcehttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/25073http://secunia.com/advisories/29129http://secunia.com/advisories/33350http://secunia.com/advisories/34642http://secunia.com/advisories/35031http://secunia.com/advisories/35062http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5587http://www.debian.org/security/2009/dsa-1799http://www.mail-archive.com/cvs-all%40freebsd.org/msg129730.htmlhttp://www.mail-archive.com/secure-testing-commits%40lists.alioth.debian.org/msg09322.htmlhttp://www.ubuntu.com/usn/usn-776-1https://bugzilla.redhat.com/show_bug.cgi?id=237342https://bugzilla.redhat.com/show_bug.cgi?id=448525https://bugzilla.redhat.com/show_bug.cgi?id=466890https://exchange.xforce.ibmcloud.com/vulnerabilities/47736https://launchpad.net/ubuntu/jaunty/+source/qemu/0.9.1+svn20081112-1ubuntu1https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01223.html
2008-12-29
Published