CVE-2008-4539: Buffer Overflow
Created attachment 320281 [details] Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)
Jan Niehusmann discovered that the upstream fix for the CVE-2007-1320 is incomplete and still allows local users to cause a heap-based buffer overlow, when connecting via the VNC console.
Steps to reproduce:
No reproducer.
Upstream qemu patch for the initial CVE-2007-1320 issue: https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch
Proposed upstream correction of this patch - see attachment.
Other sources
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4539?
CVE-2008-4539 is classified as a medium severity vulnerability due to its potential for heap overflow.
Which software versions are affected by CVE-2008-4539?
CVE-2008-4539 affects KVM versions up to 81 and QEMU versions prior to 0.10.0.
How do I fix CVE-2008-4539?
To fix CVE-2008-4539, update KVM and QEMU to the latest patched versions beyond the specified vulnerable versions.
What type of vulnerability is CVE-2008-4539?
CVE-2008-4539 is a heap overflow vulnerability that can lead to arbitrary code execution.
Is there any specific operating system vulnerability associated with CVE-2008-4539?
CVE-2008-4539 does not directly target specific operating systems but affects applications like KVM and QEMU running on various Linux distributions.