QEMU VNC Websockets Denial of Service Vulnerability


Description   A vulnerability has been reported in QEMU, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when decoding websocket packets, which can be exploited to exhaust memory resources.
     
Vulnerable Products   Vulnerable Software:
Qemu 1.xQEMU 2.x
     
Solution   Fixed in the source code repository.
     
CVE   CVE-2015-1779
     
References   Daniel P. Berrange:
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04894.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
Too much headers in HTTP request
5.0.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2015-03-25 

 Target Type 
Server 

 Possible exploit 
Remote