---
cve: "CVE-2017-2633"
severity: "MEDIUM"
cvss: 5.4
epss: "3%"
vendor: "qemu"
kev: false
exploited: false
published: "2018-07-27 19:00:00"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T07:31:57+02:00"
---

# CVE-2017-2633

> 5.4 MEDIUM

## Beschreibung

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.

## CVSS-Vektor

```
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- adba377ea7880c0aa43787fdfbadbc5f6afeaa16 (Commit)
- adba377ea7880c0aa43787fdfbadbc5f6afeaa16 (Commit)

## Referenzen

- <http://www.openwall.com/lists/oss-security/2017/02/23/1>
- <https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894ef>
- <https://access.redhat.com/errata/RHSA-2017:1206>
- <https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7>
- <https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633>
- <https://access.redhat.com/errata/RHSA-2017:1441>
- <http://www.securityfocus.com/bid/96417>
- <https://access.redhat.com/errata/RHSA-2017:1856>
- <https://access.redhat.com/errata/RHSA-2017:1205>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-2633) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
