SB2017022712 - Multiple vulnerabilities in Red Hat OpenStack 8.0 packages 



SB2017022712 - Multiple vulnerabilities in Red Hat OpenStack 8.0 packages

Published: February 27, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017022712
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2017-2615)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.


2) Out-of-bounds read (CVE-ID: CVE-2017-2620)

The vulnerability allows a remote user to gain access to potentially sensitive information.

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.


Remediation

Install update from vendor's website.