ALT-PU-2017-1158-1

Обновление пакета xen в ветке sisyphus

Версия4.8.0-alt5
Задание#178038
Опубликовано2017-02-12
Макс. серьёзностьCRITICAL
Серьёзность:

Закрытые проблемы (1)

CVE-2017-2615
CRITICAL9.1

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

Опубликовано: 2018-07-03Изменено: 2024-11-21
CVSS 2.0КРИТИЧЕСКАЯ 9.0
CVSS:2.0/AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS 3.xКРИТИЧЕСКАЯ 9.1
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Ссылки