Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3456

Опубликовано: 13 мая 2015
Источник: redhat
CVSS2: 6.5
EPSS Средний

Описание

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

An out-of-bounds memory access flaw was found in the way QEMU's virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host's QEMU process corresponding to the guest.

Отчет

This issue affects the versions of the kvm and xen packages as shipped with Red Hat Enterprise Linux 5, the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7, and the versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. Future updates for the respective releases will address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmAffected
Red Hat Enterprise Linux Extended Update Support 5.6kvmAffected
Red Hat Enterprise Linux Extended Update Support 5.6xenAffected
Red Hat Enterprise Linux Extended Update Support 5.9kvmAffected
Red Hat Enterprise Linux Extended Update Support 5.9xenAffected
Red Hat Enterprise Linux Extended Update Support 6.2qemu-kvmAffected
Red Hat Enterprise Linux Extended Update Support 6.4qemu-kvmAffected
OpenStack 4 for RHEL 6qemu-kvm-rhevFixedRHSA-2015:100413.05.2015
Red Hat Enterprise Linux 5kvmFixedRHSA-2015:100313.05.2015
Red Hat Enterprise Linux 5xenFixedRHSA-2015:100213.05.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1218611qemu: fdc: out-of-bounds fifo buffer memory access

EPSS

Процентиль: 97%
0.3391
Средний

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

nvd
больше 10 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

debian
больше 10 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and ear ...

suse-cvrf
больше 10 лет назад

Security update for Xen

github
больше 3 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

EPSS

Процентиль: 97%
0.3391
Средний

6.5 Medium

CVSS2