Red Hat update for qemu-kvm-rhev



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-9524
CWE-ID CWE-476
Exploitation vector Network
Public exploit N/A
Vulnerable software
Red Hat Virtualization
Server applications / Virtualization software

Vendor Red Hat Inc.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Null pointer dereference

EUVDB-ID: #VU7338

Risk: Low

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2017-9524

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to NULL pointer dereference in Network Block Device(NBD) Server support during a failed negotiation of a client. A remote attacker can cause the affected server to crash.

Successful exploitation of the vulnerability results in denial of service.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Virtualization: 3.0 - 4

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2017:1682


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###