CVE-2017-15124
Last modified
CVE-2017-15124 is a vulnerability of currently unknown severity. VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. EPSS estimates a 2.84% chance of exploitation in the next 30 days.
Description
VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | <= 2.11.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1525195Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1525195Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15124?
How severe is CVE-2017-15124?
How do I fix CVE-2017-15124?
Are you affected by CVE-2017-15124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
