4.9
CVSSv2

CVE-2016-4453

Published: 01/06/2016 Updated: 14/05/2020
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

canonical ubuntu linux 16.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #826152 qemu: CVE-2016-5238: scsi: esp: OOB write when using non-DMA mode in get_cmd Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 2 Jun 2016 18:54:01 UTC Severity: imp ...
USN-3047-1 introduced a regression in QEMU ...
Several security issues were fixed in QEMU ...
Quick Emulator(Qemu) built with the VMware-SVGA "chipset" emulation support is vulnerable to an infinite loop issue It could occur while processing VGA commands via its FIFO buffer A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS ...