CVE-2017-2615
qemu - security update
9.1
CRITICAL
CVSS 3.1
EPSS 3.6%
描述
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
如何修補 CVE-2017-2615
要修補 CVE-2017-2615,請將受影響套件升級到下列已修補版本。
- —升級至 2.8.1-r1 或更新版本
- —升級至 4.7.1-r5 或更新版本
- —升級至 1:2.8+dfsg-3 或更新版本
- —升級至 1.1.2+dfsg-6+deb7u20 或更新版本
- —升級至 1.1.2+dfsg-6+deb7u20 或更新版本
CVE-2017-2615 正在被利用嗎?
低 — EPSS 為 3.6%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 2.8.1-r1
- from 0, < 4.7.1-r5
- from 0, < 1:2.8+dfsg-3
- from 0, < 1.1.2+dfsg-6+deb7u20
- from 0, < 1.1.2+dfsg-6+deb7u20
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |