CVE-2008-4539
29.12.2008, 15:24
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.Enginsight
Vendor | Product | Version |
---|---|---|
kvm_qumranet | kvm | 𝑥 ≤ 81 |
qemu | qemu | 𝑥 < 0.10.0 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
debian | debian_linux | 4.0 |
debian | debian_linux | 5.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
kvm |
| ||||||||||||||||||||
qemu |
| ||||||||||||||||||||
qemu-kvm |
|
Common Weakness Enumeration
References