VDB
CVE-2008-4539
CVE-2008-4539
PUBLISHED
CVSS 7.199999809265137 HIGH
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
EPSS 0.54% · 43.0th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.54%
43.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qemu | qemu | 0 |
| n/a | n/a | * |
| canonical | ubuntu_linux | 8.04, 8.10 |
| kvm_qumranet | kvm | 0 |
| debian | debian_linux | 4.0, 5.0 |
Timeline
- Dec 29, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- 35062 third-party-advisory
- [cvs-all] 20081102 cvs commit: ports/emulators/qemu Makefile ports/emulators/qemu/files patch-CVE-2008-4539 ports/emulators/qemu-devel Makefile ports/emulators/qemu-devel/files patch-CVE-2008-4539 mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=466890 url
- USN-776-1 vendor-advisory
- 33350 third-party-advisory
- http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=5587 url
- [debian-devel-changes] 20081101 Accepted qemu 0.9.1+svn20081101-1 (source amd64) mailing-list
- 35031 third-party-advisory
- [secure-testing-commits] 20081103 r10251 - data/CVE mailing-list
- FEDORA-2008-11705 vendor-advisory
- 25073 third-party-advisory
- 34642 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=448525 url
- qemu-kvm-cirrusvga-bo(47736) vdb
- https://bugzilla.redhat.com/show_bug.cgi?id=237342 url
- SUSE-SR:2009:008 vendor-advisory
- 29129 third-party-advisory
- DSA-1799 vendor-advisory
- http://git.kernel.dk/?p=qemu.git%3Ba=commitdiff%3Bh=65d35a09979e63541afc5bfc595b9f1b1b4ae069 url
- https://launchpad.net/ubuntu/jaunty/+source/qemu/0.9.1+svn20081112-1ubuntu1 url
…and 4 more