CVE-2017-16845
Current Description
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
Basic Data
Published | November 17, 2017 |
---|---|
Last Modified | September 10, 2020 |
Assigner | cve@mitre.org |
Data Type | CVE |
Data Format | MITRE |
Data Version | 4.0 |
Problem Type | CWE-20 |
CVE Data Version | 4.0 |
Base Metric V2
CVSS 2 - Version | 2.0 |
---|---|
CVSS 2 - Vector String | AV:N/AC:L/Au:N/C:P/I:N/A:P |
CVSS 2 - Access Vector | NETWORK |
CVSS 2 - Access Complexity | LOW |
CVSS 2 - Authentication | NONE |
CVSS 2 - Confidentiality Impact | PARTIAL |
CVSS 2 - Availability Impact | PARTIAL |
CVSS 2 - Base Score | 6.4 |
Severity | MEDIUM |
Exploitability Score | 10.0 |
Impact Score | 4.9 |
Obtain All Privilege | false |
Obtain User Privilege | false |
Obtain Other Privilege | false |
Base Metric V3
No data provided.
Configurations
-
OR - Configuration 1
Cpe Version Part Vendor Product Version Update Edition Language SW Edition Target SW Target HW Other Version Start Including Version End Including Version Start Excluding Version End Excluding 2.3 Application Qemu Qemu * * * * * * * * 2.11.2 -
OR - Configuration 2
Cpe Version Part Vendor Product Version Update Edition Language SW Edition Target SW Target HW Other Version Start Including Version End Including Version Start Excluding Version End Excluding 2.3 OS Debian Debian Linux 9.0 * * * * * * * 2.3 OS Debian Debian Linux 8.0 * * * * * * * -
OR - Configuration 3
Cpe Version Part Vendor Product Version Update Edition Language SW Edition Target SW Target HW Other Version Start Including Version End Including Version Start Excluding Version End Excluding 2.3 OS Canonical Ubuntu Linux 18.04 * * * lts * * * 2.3 OS Canonical Ubuntu Linux 17.10 * * * * * * * 2.3 OS Canonical Ubuntu Linux 16.04 * * * lts * * * 2.3 OS Canonical Ubuntu Linux 14.04 * * * esm * * *
Vulnerable Software List
Vendor | Product | Versions |
---|---|---|
Debian | Debian Linux | 8.0, 9.0 |
Canonical | Ubuntu Linux | 14.04, 16.04, 17.10, 18.04 |
Qemu | Qemu | * |
References
Name | Source | URL | Tags |
---|---|---|---|
USN-3649-1 | UBUNTU | https://usn.ubuntu.com/3649-1/ | Mailing List Mailing List Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory |
USN-3575-1 | UBUNTU | https://usn.ubuntu.com/3575-1/ | Third Party Advisory VDB Entry Patch |
[qemu-devel] 20171116 [PATCH v2] ps2: check PS2Queue indices in post_load routine | MLIST | https://lists.gnu.org/archive/html/qemu-devel/2017-11/msg02982.html | Third Party Advisory |
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update | MLIST | https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html | |
101923 | BID | http://www.securityfocus.com/bid/101923 | |
DSA-4213 | DEBIAN | https://www.debian.org/security/2018/dsa-4213 |