CVE-2017-7980
published 2017-07-25CVE-2017-7980: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
46.3th percentile
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1:2.8+dfsg-4 (bookworm) | qemu 1:2.8+dfsg-4 (bookworm) |
| qemu | qemu | <= 2.8 | — |
| qemu | qemu | >= 0 < 1:2.8+dfsg-4 | 1:2.8+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-4 | 1:2.8+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-4 | 1:2.8+dfsg-4 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-4 | 1:2.8+dfsg-4 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.34 | 2.0.0+dfsg-2ubuntu1.34 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.14 | 1:2.5+dfsg-5ubuntu10.14 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w847-jx6c-6j35: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2
ghsa_unreviewed·2022-05-13
CVE-2017-7980 [HIGH] CWE-119 GHSA-w847-jx6c-6j35: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
OSV
CVE-2017-7980: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2
osv·2017-07-25·CVSS 7.8
CVE-2017-7980 [HIGH] CVE-2017-7980: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
OSV
qemu vulnerabilities
osv·2017-05-16·CVSS 6.0
CVE-2017-7377 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Li Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.
A privileged attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2017-7377, CVE-2017-8086)
Jiangxin discovered that QEMU incorrectly handled the Cirrus VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2017-7718)
Li Qiang and Jiangxin discovered that QEMU incorrectly handled the Cirrus
VGA device when being used with a VNC connection. A privileged attacker
inside the guest could use this issue to cause QEMU to crash, resulting in
a denial of service, or possibly execute arbitrary code on the host. In the
default installation, when QEMU is used with li
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2017-05-16·CVSS 6.0
CVE-2017-7377 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Li Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.
A privileged attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. (CVE-2017-7377, CVE-2017-8086)
Jiangxin discovered that QEMU incorrectly handled the Cirrus VGA device. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2017-7718)
Li Qiang and Jiangxin discovered that QEMU incorrectly handled the Cirrus
VGA device when being used with a VNC connection. A privileged attacker
inside the guest could use this issue to cause QEMU to crash, resulting in
a denial of service, or possibly execute arbitrary code on the
Red Hat
Qemu: display: cirrus: OOB r/w access issues in bitblt routines
vendor_redhat·2017-03-15·CVSS 7.8
CVE-2017-7980 [HIGH] CWE-787 Qemu: display: cirrus: OOB r/w access issues in bitblt routines
Qemu: display: cirrus: OOB r/w access issues in bitblt routines
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
An out-of-bounds r/w access issue was found in QEMU's Cirrus CLGD 54xx VGA Emulator support. The vulnerability could occur while copying VGA data via various bitblt functions. A privileged user inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
P
Debian
CVE-2017-7980: qemu - Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Q...
vendor_debian·2017·CVSS 7.8
CVE-2017-7980 [HIGH] CVE-2017-7980: qemu - Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Q...
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-4)
bullseye: resolved (fixed in 1:2.8+dfsg-4)
forky: resolved (fixed in 1:2.8+dfsg-4)
sid: resolved (fixed in 1:2.8+dfsg-4)
trixie: resolved (fixed in 1:2.8+dfsg-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
bugzilla·2017-04-21·CVSS 7.8
CVE-2017-7980 [HIGH] CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines
bugzilla·2017-04-21·CVSS 7.8
CVE-2017-7980 [HIGH] CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines
CVE-2017-7980 Qemu: display: cirrus: OOB r/w access issues in bitblt routines
Quick emulator(Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is
vulnerable to an out-of-bounds r/w access issues. It could occur while copying
VGA data via various bitblt functions.
A privileged user inside guest could use this flaw to crash the Qemu process
resulting in DoS OR potentially execute arbitrary code on a host with
privileges of Qemu process on the host.
Upstream patches:
-> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=026aeffcb4752054830ba203020ed6eb05bcaba8
-> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=ffaf857778286ca54e3804432a2369a279e73aa7
Reference:
-> http://www.openwall.com/lists/oss-security/2017/04/21/1
Discussion:
Acknowledgments:
Name: Jiangxin (PSIRT Huawei Inc.)
Bugzilla
CVE-2017-7980 xen: Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
bugzilla·2017-04-21·CVSS 7.8
CVE-2017-7980 [HIGH] CVE-2017-7980 xen: Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
CVE-2017-7980 xen: Qemu: display: cirrus: OOB r/w access issues in bitblt routines [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
http://ubuntu.com/usn/usn-3289-1http://www.openwall.com/lists/oss-security/2017/04/21/1http://www.securityfocus.com/bid/102129http://www.securityfocus.com/bid/97955https://access.redhat.com/errata/RHSA-2017:0980https://access.redhat.com/errata/RHSA-2017:0981https://access.redhat.com/errata/RHSA-2017:0982https://access.redhat.com/errata/RHSA-2017:0983https://access.redhat.com/errata/RHSA-2017:0984https://access.redhat.com/errata/RHSA-2017:0988https://access.redhat.com/errata/RHSA-2017:1205https://access.redhat.com/errata/RHSA-2017:1206https://access.redhat.com/errata/RHSA-2017:1430https://access.redhat.com/errata/RHSA-2017:1441https://bugzilla.redhat.com/show_bug.cgi?id=1430056https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://security.gentoo.org/glsa/201706-03https://support.citrix.com/article/CTX230138http://ubuntu.com/usn/usn-3289-1http://www.openwall.com/lists/oss-security/2017/04/21/1http://www.securityfocus.com/bid/102129http://www.securityfocus.com/bid/97955https://access.redhat.com/errata/RHSA-2017:0980https://access.redhat.com/errata/RHSA-2017:0981https://access.redhat.com/errata/RHSA-2017:0982https://access.redhat.com/errata/RHSA-2017:0983https://access.redhat.com/errata/RHSA-2017:0984https://access.redhat.com/errata/RHSA-2017:0988https://access.redhat.com/errata/RHSA-2017:1205https://access.redhat.com/errata/RHSA-2017:1206https://access.redhat.com/errata/RHSA-2017:1430https://access.redhat.com/errata/RHSA-2017:1441https://bugzilla.redhat.com/show_bug.cgi?id=1430056https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://security.gentoo.org/glsa/201706-03https://support.citrix.com/article/CTX230138
2017-07-25
Published