CVE-2008-2382: Medium severity qemu vulnerability
The protocolclientmsg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2382?
CVE-2008-2382 is classified as a denial of service vulnerability due to the potential for an infinite loop caused by malformed messages.
How do I fix CVE-2008-2382?
To fix CVE-2008-2382, upgrade to a version of QEMU later than 0.9.1 or KVM later than version 79.
Which versions are affected by CVE-2008-2382?
CVE-2008-2382 affects QEMU versions up to 0.9.1 and KVM versions up to kvm-79.
What types of attacks are possible with CVE-2008-2382?
An attacker can exploit CVE-2008-2382 to send specific messages that trigger an infinite loop, leading to denial of service.
Is CVE-2008-2382 publicly known?
Yes, CVE-2008-2382 is a publicly disclosed vulnerability and details are available in security advisories.