CVE-2013-0241
published 2013-02-13CVE-2013-0241: The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.39%
31.3th percentile
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | xserver-xorg-video-qxl | < xserver-xorg-video-qxl 0.0.17-1 (bookworm) | xserver-xorg-video-qxl 0.0.17-1 (bookworm) |
| qxl_graphics_driver_project | xf86-video-qxl | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QXL graphics driver vulnerability
vendor_ubuntu·2013-02-05
CVE-2013-0241 QXL graphics driver vulnerability
Title: QXL graphics driver vulnerability
Summary: Guests using the QXL graphics driver could be caused to hang or crash.
It was discovered that the QXL graphics driver incorrectly handled
terminated connections. An attacker that could connect to a guest using
SPICE and the QXL graphics driver could cause the guest to hang or crash,
resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2013-0241: xserver-xorg-video-qxl - The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a de...
vendor_debian·2013·CVSS 2.1
CVE-2013-0241 [LOW] CVE-2013-0241: xserver-xorg-video-qxl - The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a de...
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.0.17-1)
bullseye: resolved (fixed in 0.0.17-1)
forky: resolved (fixed in 0.0.17-1)
sid: resolved (fixed in 0.0.17-1)
trixie: resolved (fixed in 0.0.17-1)
Red Hat
qxl: synchronous io guest DoS
vendor_redhat·2011-08-03·CVSS 2.1
CVE-2013-0241 [LOW] qxl: synchronous io guest DoS
qxl: synchronous io guest DoS
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
Package: xorg-x11-drv-qxl (Red Hat Enterprise Linux 5) - Under investigation
GHSA
GHSA-6x5v-pqrf-rh9v: The QXL display driver in QXL Virtual GPU 0
ghsa_unreviewed·2022-05-05
CVE-2013-0241 [LOW] GHSA-6x5v-pqrf-rh9v: The QXL display driver in QXL Virtual GPU 0
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
OSV
CVE-2013-0241: The QXL display driver in QXL Virtual GPU 0
osv·2013-02-13·CVSS 2.1
CVE-2013-0241 [LOW] CVE-2013-0241: The QXL display driver in QXL Virtual GPU 0
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0218.htmlhttp://secunia.com/advisories/52021http://www.mandriva.com/security/advisories?name=MDVSA-2013:138http://www.openwall.com/lists/oss-security/2013/01/30/3http://www.openwall.com/lists/oss-security/2013/01/30/4http://www.ubuntu.com/usn/USN-1714-1https://bugzilla.redhat.com/show_bug.cgi?id=906032https://exchange.xforce.ibmcloud.com/vulnerabilities/81704https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0036http://rhn.redhat.com/errata/RHSA-2013-0218.htmlhttp://secunia.com/advisories/52021http://www.mandriva.com/security/advisories?name=MDVSA-2013:138http://www.openwall.com/lists/oss-security/2013/01/30/3http://www.openwall.com/lists/oss-security/2013/01/30/4http://www.ubuntu.com/usn/USN-1714-1https://bugzilla.redhat.com/show_bug.cgi?id=906032https://exchange.xforce.ibmcloud.com/vulnerabilities/81704https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0036
2013-02-13
Published