CVE-2008-2382

NameCVE-2008-2382
DescriptionThe protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qemu (PTS)wheezy1.1.2+dfsg-6a+deb7u12fixed
wheezy (security)1.1.2+dfsg-6+deb7u23fixed
jessie (security), jessie1:2.1+dfsg-12+deb8u6fixed
stretch1:2.8+dfsg-6fixed
stretch (security)1:2.8+dfsg-6+deb9u2fixed
buster, sid1:2.8+dfsg-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kvmsource(unstable)72+dfsg-4medium
qemusource(unstable)0.9.1-9medium
qemusourceetch(not affected)
xen-3source(unstable)(not affected)
xen-unstablesource(unstable)(not affected)

Notes

[etch] - qemu <not-affected> (Tested by maintainer)
- xen-unstable <not-affected> (Vulnerable code not present)
- xen-3 <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems