CVE-2008-2382

NameCVE-2008-2382
DescriptionThe protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)stretch1:2.8+dfsg-6+deb9u9fixed
stretch (security)1:2.8+dfsg-6+deb9u11fixed
buster, buster (security)1:3.1+dfsg-8+deb10u8fixed
bullseye, sid1:5.1+dfsg-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kvmsource(unstable)72+dfsg-4
qemusourceetch(not affected)
qemusource(unstable)0.9.1-9
xen-3source(unstable)(not affected)
xen-unstablesource(unstable)(not affected)

Notes

[etch] - qemu <not-affected> (Tested by maintainer)
- xen-unstable <not-affected> (Vulnerable code not present)
- xen-3 <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems