CVE-2017-15124
Summary
| CVE | CVE-2017-15124 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-09 21:29:00 UTC |
| Updated | 2023-02-12 23:28:00 UTC |
| Description | VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| USN-3575-1: QEMU vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE-2017-15124 - Red Hat Customer Portal | MISC | access.redhat.com | |
| 1525195 – (CVE-2017-15124) CVE-2017-15124 Qemu: memory exhaustion through framebuffer update request message in VNC server | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Debian -- Security Information -- DSA-4213-1 qemu | DEBIAN | www.debian.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| QEMU CVE-2017-15124 Denial of Service Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.