QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
BID:36716
Info
QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
| Bugtraq ID: | 36716 |
| Class: | Design Error |
| CVE: |
CVE-2009-3616 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2009 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | Enrico Scholz |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Redhat Enterprise Linux 5 Server QEMU QEMU 0.10 QEMU QEMU 0 Pardus Linux 2009 0 |
| Not Vulnerable: |
QEMU QEMU 0.10.6 |
Discussion
QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
QEMU is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
QEMU is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
QEMU VNC Client Disconnect Use After Free Remote Code Execution Vulnerability
References:
References:
- Bug 501131 qemu segfault when VNC client disconnects (Enrico Scholz)
- Bug 505641 Remote VNC client can cause any QEMU VNC server to crash with a doubl (Daniel Berrange)
- New package: kvm (Red Hat)
- QEMU Homepage (QEMU)
- Support multiple VNC clients (Brian Kress) (Brian Kress)
- vnc: rework VncState release workflow. (Gerd Hoffmann)