BF Specification of CVE-2008-4539 “BitBlt” heap overflow in Cirrus VGA in KVM before kvm-82 and QEMU on Debian GNU/Linux and Ubuntu

../../../../BF/images/BFVUL/CVE-2008-4539(simple)-0.png
Erroneous verification of pointers towards a upper limit leads to use of an inconsistent size for an object, allowing a pointer reposition over its bounds, which, when used to in 'cirrus_do_copy()' leads to a heap buffer overflow. If exploited, this can lead to arbitrary code execution.

//generated// Erroneous Code (in ‘cirrus_bitblt_videotovideo_copy() misplaced ‘BLTUNSAFE(s)’ check) to Verify via Range (fixed with trancation via ‘& s->cirrus_addr_mask’) of In Use in Codebase (hw/cirrus_vga.c#L793-#L796) Bare-Metal (Xen bare-metal hypervisor) leads to Wrong Value , which propagates to Wrong Size Direct Reposition (‘cirrus_do_copy()’) Heap Used Codebase (hw/cirrus_vga.c#L789-#L791) in Bare-Metal (Xen bare-metal hypervisor) that results in Overbound Pointer , which propagates to Overbound Pointer (in e.g., ‘cpu_physical_memory_set_dirty(s->vram_offset + off_cur)’) Direct Write Heap Codebase (hw/cirrus_vga.c#L789-#L791) in Bare-Metal (Xen bare-metal hypervisor) that results in Buffer Overflow , which can be exploited toward Arbitrary Code Execution (ACE) - everything could be lost security failure.



vendor:product: kvm_qumranet:kvm


Bug Report


Code with Fix


Code with Bug


NVD Entry

ClassDefinition
OperationDefinition
Cause/ConsequenceDefinition
Code BugCode Bug type – An error in the implementation of an operation – proper operands over an improper operation. It is the roor cause of a security vulnerability. Must be fixed to resolve the vulnerability.
   Erroneous CodeErroneous Code bug - There is a coding error in the implementation of the operation.
Data Error/FaultData error (or fault) type – The data of an object has harmed semantics or inconsistent or wrong value.
   Wrong ValueWrong Value error (or fault) – The data value is not accurate (e.g., outside of a range).
   Wrong SizeWrong Size error (or fault) – The value used as size or length (i.e., the number of elements) does not match the object's memory size or length (e.g., to limit a pointer reposition or index increment/decrement in a repetition statement).
Address Error/FaultAddress error (or fault) type – The address of an object is wrong.
   Overbound PointerOverbound Pointer error (or fault) – Holds an address that is above the upper boundary of its object.
Memory Corruption/Disclosure Final ErrorMemory Corruption/Disclosure final error/exploit vector type – An exploitable or undefined system behavior caused by memory addressing, allocation, use, or deallocation bugs.
   Buffer OverflowBuffer Overflow final error – Write data above the upper bound of an object (i.e., buffer over-write).
Operation AttributeDefinition
MechanismMechanism operation attribute type – Shows how the operation with a bug or faulty operand is performed.
   RangeRange operation attribute – The operation checks data are within a (min, max) interval.
   DirectDirect operation attribute – The operation is on a particular object element.
Source CodeSource Code operation attribute type – Shows where the code of the operation with a bug or faulty operand resides within the software, firmware, or hardware.
   CodebaseCodebase operation attribute – The operation is in the programmer's code - in the application itself.
Execution SpaceExecution Space operation attribute type – Shows where the operation with a bug or faulty operand is executed and the privilege level at which it runs.
   Bare-MetalBare-Metal operation attribute – The bugged code runs in an environment without privilege control. Usually, the program is the only software running and has total access to the hardware.
Operand AttributeDefinition
Data StateData State operand attribute type – Shows where the data comes from.
   In UseIn Use operand attribute – Data are from a volatile storage (e.g., RAM, cache memory).
Address StateAddress State operand attribute type – Shows where the address is (i.e., its location) in the memory layout.
   HeapThe object is a dynamically allocated data structure (e.g., via malloc() or new).
Size KindSize Kind operand attribute type – Shows what is used as the size or length (i.e., the number of elements) of an object - e.g., as the limit for traversal over the elements.
   UsedUsed operand attribute – A supplied value to be used as the size or length (i.e., the number of elements) of an object.