CVE-2017-5956
published 2017-03-20CVE-2017-5956: The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.4th percentile
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virglrenderer | < virglrenderer 0.6.0-1 (bookworm) | virglrenderer 0.6.0-1 (bookworm) |
| virglrenderer_project | virglrenderer | <= 0.5.0 | — |
| virglrenderer_project | virglrenderer | >= 0 < 0.6.0-1 | 0.6.0-1 |
| virglrenderer_project | virglrenderer | >= 0 < 0.6.0-1 | 0.6.0-1 |
| virglrenderer_project | virglrenderer | >= 0 < 0.6.0-1 | 0.6.0-1 |
| virglrenderer_project | virglrenderer | >= 0 < 0.6.0-1 | 0.6.0-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libphp-phpmailer vulnerability
osv·2023-03-15·CVSS 9.8
CVE-2017-11503 libphp-phpmailer vulnerability
libphp-phpmailer vulnerability
USN-5956-1 fixed vulnerabilities in PHPMailer. It was discovered that the
fix for CVE-2017-11503 was incomplete. This update fixes the problem.
Original advisory details:
Dawid Golunski discovered that PHPMailer was not properly escaping user
input data used as arguments to functions executed by the system shell. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045)
It was discovered that PHPMailer was not properly escaping characters
in certain fields of the code_generator.php example code. An attacker
could possibly use this issue to conduct cross-site scripting (XSS)
attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04
ESM. (CVE-2017-11503)
Yo
GHSA
GHSA-rmf6-f9hp-cjxh: The vrend_draw_vbo function in virglrenderer before 0
ghsa_unreviewed·2022-05-17
CVE-2017-5956 [MEDIUM] CWE-125 GHSA-rmf6-f9hp-cjxh: The vrend_draw_vbo function in virglrenderer before 0
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
OSV
CVE-2017-5956: The vrend_draw_vbo function in virglrenderer before 0
osv·2017-03-20·CVSS 5.5
CVE-2017-5956 [MEDIUM] CVE-2017-5956: The vrend_draw_vbo function in virglrenderer before 0
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
Debian
CVE-2017-5956: virglrenderer - The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS ...
vendor_debian·2017·CVSS 5.5
CVE-2017-5956 [MEDIUM] CVE-2017-5956: virglrenderer - The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS ...
The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.
Scope: local
bookworm: resolved (fixed in 0.6.0-1)
bullseye: resolved (fixed in 0.6.0-1)
forky: resolved (fixed in 0.6.0-1)
sid: resolved (fixed in 0.6.0-1)
trixie: resolved (fixed in 0.6.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5956 Virglrenderer: OOB access while in vrend_draw_vbo
bugzilla·2017-02-10·CVSS 5.5
CVE-2017-5956 [MEDIUM] CVE-2017-5956 Virglrenderer: OOB access while in vrend_draw_vbo
CVE-2017-5956 Virglrenderer: OOB access while in vrend_draw_vbo
Virgil 3d project, used by Quick Emulator(Qemu) to implement 3D GPU support
for the virtio GPU, is vulnerable to an OOB array access issue. It could occur
when in vrend_draw_vbo.
A guest user/process could use this flaw to crash the Qemu process instance
resulting DoS.
Upstream patch:
-> https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95d
Reference:
-> http://www.openwall.com/lists/oss-security/2017/02/13/2
Discussion:
Acknowledgments:
Name: Li Qiang (360.cn Inc.)
---
Created virglrenderer tracking bugs for this issue:
Affects: fedora-all [bug 1421074]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a comm
Bugzilla
CVE-2017-5956 virglrenderer: Virglrenderer: OOB access while in vrend_draw_vbo [fedora-all]
bugzilla·2017-02-10·CVSS 5.5
CVE-2017-5956 [MEDIUM] CVE-2017-5956 virglrenderer: Virglrenderer: OOB access while in vrend_draw_vbo [fedora-all]
CVE-2017-5956 virglrenderer: Virglrenderer: OOB access while in vrend_draw_vbo [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
http://www.openwall.com/lists/oss-security/2017/02/13/2http://www.securityfocus.com/bid/96187https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95dhttps://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.htmlhttps://security.gentoo.org/glsa/201707-06http://www.openwall.com/lists/oss-security/2017/02/13/2http://www.securityfocus.com/bid/96187https://cgit.freedesktop.org/virglrenderer/commit/?id=a5ac49940c40ae415eac0cf912eac7070b4ba95dhttps://lists.freedesktop.org/archives/virglrenderer-devel/2017-February/000145.htmlhttps://security.gentoo.org/glsa/201707-06
2017-03-20
Published