{"api_version":"1","generated_at":"2026-07-23T05:44:23+00:00","cve":"CVE-2017-15124","urls":{"html":"https://cve.report/CVE-2017-15124","api":"https://cve.report/api/cve/CVE-2017-15124.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15124","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15124"},"summary":{"title":"CVE-2017-15124","description":"VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-01-09 21:29:00","updated_at":"2023-02-12 23:28:00"},"problem_types":["CWE-770"],"metrics":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2018:1104","name":"RHSA-2018:1104","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3575-1/","name":"USN-3575-1","refsource":"UBUNTU","tags":[],"title":"USN-3575-1: QEMU vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:1113","name":"RHSA-2018:1113","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:3062","name":"RHSA-2018:3062","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2017-15124","name":"https://access.redhat.com/security/cve/CVE-2017-15124","refsource":"MISC","tags":[],"title":"CVE-2017-15124 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1525195","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1525195","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1525195 – (CVE-2017-15124) CVE-2017-15124 Qemu: memory exhaustion through framebuffer update request message in VNC server","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2018/dsa-4213","name":"DSA-4213","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4213-1 qemu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:0816","name":"RHSA-2018:0816","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102295","name":"102295","refsource":"BID","tags":[],"title":"QEMU CVE-2017-15124 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15124","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15124","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15124","vulnerable":"1","versionEndIncluding":"2.11.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qemu","cpe5":"qemu","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2017-15124","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-770","cweId":"CWE-770"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"QEMU","product":{"product_data":[{"product_name":"Qemu","version":{"version_data":[{"version_affected":"=","version_value":"2.11.0 and older"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.securityfocus.com/bid/102295","refsource":"MISC","name":"http://www.securityfocus.com/bid/102295"},{"url":"https://access.redhat.com/errata/RHSA-2018:0816","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:0816"},{"url":"https://access.redhat.com/errata/RHSA-2018:1104","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:1104"},{"url":"https://access.redhat.com/errata/RHSA-2018:1113","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:1113"},{"url":"https://access.redhat.com/errata/RHSA-2018:3062","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:3062"},{"url":"https://usn.ubuntu.com/3575-1/","refsource":"MISC","name":"https://usn.ubuntu.com/3575-1/"},{"url":"https://www.debian.org/security/2018/dsa-4213","refsource":"MISC","name":"https://www.debian.org/security/2018/dsa-4213"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1525195","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1525195"}]}},"nvd":{"publishedDate":"2018-01-09 21:29:00","lastModifiedDate":"2023-02-12 23:28:00","problem_types":["CWE-770"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":7.8},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","versionEndIncluding":"2.11.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15124","Ordinal":"112626","Title":"CVE-2017-15124","CVE":"CVE-2017-15124","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15124","Ordinal":"1","NoteData":"VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"15124","Ordinal":"2","NoteData":"2018-01-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15124","Ordinal":"3","NoteData":"2018-10-31","Type":"Other","Title":"Modified"}]}}}