CVE-2014-3689
qemu-kvm - security update
EPSS 0.09%
Description
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
How to fix CVE-2014-3689
To remediate CVE-2014-3689, upgrade the affected package to a fixed version below.
- Debian/qemu—upgrade to 2.1+dfsg-6 or later
- Debian/qemu—upgrade to 1.1.2+dfsg-6a+deb7u5 or later
- Debian/qemu-kvm—upgrade to 1.1.2+dfsg-6+deb7u5 or later
Is CVE-2014-3689 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.1+dfsg-6
- from 0, < 1.1.2+dfsg-6a+deb7u5
- from 0, < 1.1.2+dfsg-6+deb7u5