7.2

CVE-2014-3689

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version <= 2.1.3
Debian ≫ Debian Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.304
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://www.ubuntu.com/usn/USN-2409-1
Third Party Advisory
http://secunia.com/advisories/60923
Third Party Advisory
http://secunia.com/advisories/62143
Third Party Advisory
http://secunia.com/advisories/62144
Third Party Advisory
http://www.debian.org/security/2014/dsa-3066
Third Party Advisory
http://www.debian.org/security/2014/dsa-3067
Third Party Advisory
http://www.osvdb.org/114397
Broken Link
https://www.mail-archive.com/qemu-devel%40nongnu.org/msg261580.html