CVE-2018-5683Out-of-bounds Read in Qemu

CWE-125Out-of-bounds Read13 documents8 sources
Severity
6.0MEDIUMNVD
OSV4.4
EPSS
0.0%
top 91.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 13

Description

The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 1.5 | Impact: 4.0

Affected Packages6 packages

Debianqemu/qemu< 1:2.12~rc3+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.39+3
NVDqemu/qemu2.11.1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, Enterprise Linux 7.6, 7.7

Patches

🔴Vulnerability Details

5
GHSA
GHSA-4v68-h86g-72p3: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by2022-05-13
OSV
qemu regression2018-03-05
OSV
qemu vulnerabilities2018-02-20
OSV
CVE-2018-5683: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by2018-01-23
CVEList
CVE-2018-5683: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by2018-01-23

📋Vendor Advisories

4
Ubuntu
QEMU regression2018-03-05
Ubuntu
QEMU vulnerabilities2018-02-20
Debian
CVE-2018-5683: qemu - The vga_draw_text function in Qemu allows local OS guest privileged users to cau...2018
Red Hat
Qemu: Out-of-bounds read in vga_draw_text routine2017-12-25

💬Community

3
Bugzilla
CVE-2018-5683 qemu: Out-of-bounds read in vga_draw_text function in hw/display/vga.c [fedora-all]2018-01-15
Bugzilla
CVE-2018-5683 xen: Qemu: Out-of-bounds read in vga_draw_text routine [fedora-all]2018-01-15
Bugzilla
CVE-2018-5683 Qemu: Out-of-bounds read in vga_draw_text routine2018-01-02
CVE-2018-5683 — Out-of-bounds Read in Qemu | cvebase