Total vulnerabilities in the database
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Software | From | Fixed in |
---|---|---|
kvm_qumranet / kvm | - | 81.x |
qemu / qemu | - | 0.10.0 |
canonical / ubuntu_linux | 8.10 | 8.10.x |
canonical / ubuntu_linux | 8.04 | 8.04.x |
debian / debian_linux | 5.0 | 5.0.x |
debian / debian_linux | 4.0 | 4.0.x |