Back to search
CVE-2014-8106
Published: Dec 8, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20141204 CVE-2014-8106 qemu: cirrus: insufficient blit region checks
mailing-list
x_refsource_MLIST
RHSA-2015:0795
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0624
vendor-advisory
x_refsource_REDHAT
FEDORA-2015-5482
vendor-advisory
x_refsource_FEDORA
RHSA-2015:0891
vendor-advisory
x_refsource_REDHAT
71477
vdb-entry
x_refsource_BID
RHSA-2015:0643
vendor-advisory
x_refsource_REDHAT
qemu-cve20148106-sec-bypass(99126)
vdb-entry
x_refsource_XF
60364
third-party-advisory
x_refsource_SECUNIA
RHSA-2015:0349
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0868
vendor-advisory
x_refsource_REDHAT
[Qemu-devel] 20141204 [PULL for-2.2 0/2] cirrus: fix blit region check (cve-2014-8106)
mailing-list
x_refsource_MLIST
DSA-3088
vendor-advisory
x_refsource_DEBIAN
http://support.citrix.com/article/CTX200892
x_refsource_CONFIRM
DSA-3087
vendor-advisory
x_refsource_DEBIAN
RHSA-2015:0867
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now