VDB
CVE-2009-3616
CVE-2009-3616
PUBLISHED
CVSS 8.5 HIGH
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
EPSS 0.75% · 73.6th percentile
Risk Scores
CVSS 2.0
8.5
EPSS Score
0.75%
73.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| qemu | qemu | 0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_workstation | 5.0 |
Timeline
- Oct 23, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=501131 url
- http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=753b405331 url
- [oss-security] 20091016 Re: QEMU VNC use-after-free mailing-list
- http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=198a0039c5 url
- [qemu-devel] 20090525 Re: [STABLE] [BUG] VNC mode can crash QEMU mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=508567 url
- 36716 vdb
- http://rhn.redhat.com/errata/RHEA-2009-1272.html url
- [oss-security] 20091016 QEMU VNC use-after-free mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=505641 url
- https://nvd.nist.gov/vuln/detail/CVE-2009-3616 advisory