Improper Memory Address Validation in QEMU's vga_draw_text Function Allows for Denial of Service

Improper Memory Address Validation in QEMU's vga_draw_text Function Allows for Denial of Service

CVE-2018-5683 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.

Learn more about our User Device Pen Test.