cbcvebase.
CVE-2018-5683
published 2018-01-23

CVE-2018-5683: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by…

medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.12~rc3+dfsg-1 (bookworm)qemu 1:2.12~rc3+dfsg-1 (bookworm)
qemuqemu<= 2.11.1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 1:2.12~rc3+dfsg-11:2.12~rc3+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.392.0.0+dfsg-2ubuntu1.39
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.402.0.0+dfsg-2ubuntu1.40
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.221:2.5+dfsg-5ubuntu10.22
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.241:2.5+dfsg-5ubuntu10.24
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
osv6.0MEDIUM