Lucene search

K
nvd[email protected]NVD:CVE-2023-3354
HistoryJul 11, 2023 - 5:15 p.m.

CVE-2023-3354

2023-07-1117:15:13
CWE-476
web.nvd.nist.gov
5
qemu
vnc server
remote unauthenticated client
denial of service
null pointer dereference

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.

Affected configurations

NVD
Node
qemuqemuRange<8.1.0
OR
qemuqemuMatch8.1.0rc0
OR
qemuqemuMatch8.1.0rc1
Node
redhatopenstack_platformMatch13.0
OR
redhatenterprise_linuxMatch7.0
OR
redhatenterprise_linuxMatch8.0-
OR
redhatenterprise_linuxMatch8.0advanced_virtualization
OR
redhatenterprise_linuxMatch9.0
Node
fedoraprojectfedoraMatch38

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%