Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
QEMU 资源管理错误漏洞
Vulnerability Description
QEMU是一套由Fabrice Bellard所编写的开源跨平台模拟器。 QEMU VNC服务器中的vnc.c存在多个安全漏洞,这些漏洞与double free漏洞有关。Guest用户可以先从VNC客户端建立一个连接,然后在数据传输过程中断开连接,使用错误的整型数据类型或模糊屏幕模式协议发送信息,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A