CVE-2009-3616
published 2009-10-23CVE-2009-3616: Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host…
PriorityP354critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
3.88%
89.1th percentile
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 0.11.0-1 (bookworm) | qemu 0.11.0-1 (bookworm) |
| qemu | qemu | <= 0.10.6 | — |
| qemu | qemu | >= 0 < 0.11.0-1 | 0.11.0-1 |
| qemu | qemu | >= 0 < 0.11.0-1 | 0.11.0-1 |
| qemu | qemu | >= 0 < 0.11.0-1 | 0.11.0-1 |
| qemu | qemu | >= 0 < 0.11.0-1 | 0.11.0-1 |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv9.9CRITICAL
vendor_debian9.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmwq-xc6v-xj4j: Multiple use-after-free vulnerabilities in vnc
ghsa_unreviewed·2022-05-02
CVE-2009-3616 [HIGH] CWE-416 GHSA-vmwq-xc6v-xj4j: Multiple use-after-free vulnerabilities in vnc
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
OSV
CVE-2009-3616: Multiple use-after-free vulnerabilities in vnc
osv·2009-10-23·CVSS 9.9
CVE-2009-3616 [CRITICAL] CVE-2009-3616: Multiple use-after-free vulnerabilities in vnc
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
Debian
CVE-2009-3616: qemu - Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10....
vendor_debian·2009·CVSS 9.9
CVE-2009-3616 [CRITICAL] CVE-2009-3616: qemu - Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10....
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
Scope: local
bookworm: resolved (fixed in 0.11.0-1)
bullseye: resolved (fixed in 0.11.0-1)
forky: resolved (fixed in 0.11.0-1)
sid: resolved (fixed in 0.11.0-1)
trixie: resolved (fixed in 0.11.0-1)
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=198a0039c5http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=753b405331http://marc.info/?l=qemu-devel&m=124324043812915http://rhn.redhat.com/errata/RHEA-2009-1272.htmlhttp://www.openwall.com/lists/oss-security/2009/10/16/5http://www.openwall.com/lists/oss-security/2009/10/16/8http://www.securityfocus.com/bid/36716https://bugzilla.redhat.com/show_bug.cgi?id=501131https://bugzilla.redhat.com/show_bug.cgi?id=505641https://bugzilla.redhat.com/show_bug.cgi?id=508567http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=198a0039c5http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=753b405331http://marc.info/?l=qemu-devel&m=124324043812915http://rhn.redhat.com/errata/RHEA-2009-1272.htmlhttp://www.openwall.com/lists/oss-security/2009/10/16/5http://www.openwall.com/lists/oss-security/2009/10/16/8http://www.securityfocus.com/bid/36716https://bugzilla.redhat.com/show_bug.cgi?id=501131https://bugzilla.redhat.com/show_bug.cgi?id=505641https://bugzilla.redhat.com/show_bug.cgi?id=508567
2009-10-23
Published