A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 6.5 | Medium | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Product | Vendor | Version |
---|---|---|
Red Hat Enterprise Linux 6 | Red Hat | <= 2.4.7 |
Red Hat Enterprise Linux 9 | Red Hat | <= 12.2.x.x |
Red Hat Enterprise Linux 7 | Red Hat | < 9.5 |
Red Hat Enterprise Linux 7 | Red Hat | n/a |
Red Hat Enterprise Linux 8 Advanced Virtualization | Red Hat | n/a |
Red Hat Enterprise Linux 8 | Red Hat | 17.6.6 |
Red Hat Enterprise Linux 8 | Red Hat | <= 1.5 |