CVE-2017-2633
published 2018-07-27CVE-2017-2633: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
3.04%
86.1th percentile
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.1+dfsg-1 (bookworm) | qemu 2.1+dfsg-1 (bookworm) |
| qemu | qemu | < 1.7.2 | 1.7.2 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.33 | 2.0.0+dfsg-2ubuntu1.33 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.11 | 1:2.5+dfsg-5ubuntu10.11 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c46f-47cq-c2fg: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1
ghsa_unreviewed·2022-05-13
CVE-2017-2633 [MEDIUM] CWE-125 GHSA-c46f-47cq-c2fg: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
OSV
CVE-2017-2633: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1
osv·2018-07-27·CVSS 6.5
CVE-2017-2633 [MEDIUM] CVE-2017-2633: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
OSV
qemu vulnerabilities
osv·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)
It was disc
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ub
Debian
CVE-2017-2633: qemu - An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1...
vendor_debian·2017·CVSS 5.4
CVE-2017-2633 [MEDIUM] CVE-2017-2633: qemu - An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1...
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
Red Hat
Qemu: VNC: memory corruption due to unchecked resolution limit
vendor_redhat·2016-12-01·CVSS 5.4
CVE-2017-2633 [MEDIUM] CWE-120 Qemu: VNC: memory corruption due to unchecked resolution limit
Qemu: VNC: memory corruption due to unchecked resolution limit
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
Package: kvm (Red Hat Enterprise Linux 5) - Affected
Package: xen (Red Hat Enterprise Linux 5) - Affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Affected
Pac
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2633 Qemu: VNC: memory corruption due to unchecked resolution limit
bugzilla·2017-02-22·CVSS 5.4
CVE-2017-2633 [MEDIUM] CVE-2017-2633 Qemu: VNC: memory corruption due to unchecked resolution limit
CVE-2017-2633 Qemu: VNC: memory corruption due to unchecked resolution limit
Quick Emulator(Qemu) built with the VNC display driver support is vulnerable
to an out-of-bounds memory access issue. It could occur while refreshing
the vnc display surface area in 'vnc_refresh_server_surface'.
A user/process inside guest could use this flaw to crash the Qemu process
resulting in DoS.
Older versions of Qemu are affected, latest upstream releases are not.
Upstream patch:
-> http://git.qemu-project.org/?p=qemu.git;a=commitdiff;h=bea60dd7679364493a0d7f5b54316c767cf894ef
-> http://git.qemu-project.org/?p=qemu.git;a=commitdiff;h=9f64916da20eea67121d544698676295bbb105a7
Reference:
-> http://www.openwall.com/lists/oss-security/2017/02/23/1
Discussion:
This issue has been addressed in the followin
Bugzilla
CVE-2017-2633 qemu-kvm coredump in vnc_refresh_server_surface [rhel-6.9.z]
bugzilla·2016-12-01·CVSS 5.4
CVE-2017-2633 [MEDIUM] CVE-2017-2633 qemu-kvm coredump in vnc_refresh_server_surface [rhel-6.9.z]
CVE-2017-2633 qemu-kvm coredump in vnc_refresh_server_surface [rhel-6.9.z]
Looks like this one won't make it into 6.9; Moving to 6.9.z.
Discussion:
Fix included in qemu-kvm-0.12.1.2-2.503.el6_9.1
---
Verified per comment https://bugzilla.redhat.com/show_bug.cgi?id=1425943#c5
---
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2017:1206
http://www.openwall.com/lists/oss-security/2017/02/23/1http://www.securityfocus.com/bid/96417https://access.redhat.com/errata/RHSA-2017:1205https://access.redhat.com/errata/RHSA-2017:1206https://access.redhat.com/errata/RHSA-2017:1441https://access.redhat.com/errata/RHSA-2017:1856https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894efhttp://www.openwall.com/lists/oss-security/2017/02/23/1http://www.securityfocus.com/bid/96417https://access.redhat.com/errata/RHSA-2017:1205https://access.redhat.com/errata/RHSA-2017:1206https://access.redhat.com/errata/RHSA-2017:1441https://access.redhat.com/errata/RHSA-2017:1856https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894ef
2018-07-27
Published