Description
* A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA
emulator's VNC display driver support; the issue could occur when a VNC client
attempted to update its display after a VGA operation is performed by a guest. A
privileged user/process inside a guest could use this flaw to crash the QEMU
process or, potentially, execute arbitrary code on the host with privileges of
the QEMU process. (CVE-2016-9603)
* An out-of-bounds r/w access issue was found in QEMU's Cirrus CLGD 54xx VGA
Emulator support. The vulnerability could occur while copying VGA data via
various bitblt functions. A privileged user inside a guest could use this flaw
to crash the QEMU process or, potentially, execute arbitrary code on the host
with privileges of the QEMU process. (CVE-2017-7980)
* An out-of-bounds memory access issue was found in QEMU's VNC display driver
support. The vulnerability could occur while refreshing the VNC display surface
area in the 'vnc_refresh_server_surface'. A user/process inside a guest could
use this flaw to crash the QEMU process, resulting in a denial of service.
(CVE-2017-2633)
* An out-of-bounds access issue was found in QEMU's Cirrus CLGD 54xx VGA
Emulator support. The vulnerability could occur while copying VGA data using
bitblt functions (for example, cirrus_bitblt_rop_fwd_transp_). A privileged user
inside a guest could use this flaw to crash the QEMU process, resulting in
denial of service. (CVE-2017-7718)