Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3456

Опубликовано: 13 мая 2015
Источник: redhat
CVSS2: 6.5
EPSS Средний

Описание

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

An out-of-bounds memory access flaw was found in the way QEMU's virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host's QEMU process corresponding to the guest.

Отчет

This issue affects the versions of the kvm and xen packages as shipped with Red Hat Enterprise Linux 5, the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7, and the versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virtualization 3. Future updates for the respective releases will address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmAffected
OpenStack 4 for RHEL 6qemu-kvm-rhevFixedRHSA-2015:100413.05.2015
Red Hat Enterprise Linux 5kvmFixedRHSA-2015:100313.05.2015
Red Hat Enterprise Linux 5xenFixedRHSA-2015:100213.05.2015
Red Hat Enterprise Linux 6qemu-kvmFixedRHSA-2015:099813.05.2015
Red Hat Enterprise Linux 6.5 Extended Update Supportqemu-kvmFixedRHSA-2015:103127.05.2015
Red Hat Enterprise Linux 7qemu-kvmFixedRHSA-2015:099913.05.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6qemu-kvm-rhevFixedRHSA-2015:100413.05.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qemu-kvm-rhevFixedRHSA-2015:100413.05.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7qemu-kvm-rhevFixedRHSA-2015:100413.05.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1218611qemu: fdc: out-of-bounds fifo buffer memory access

EPSS

Процентиль: 96%
0.15275
Средний

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

nvd
около 11 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

debian
около 11 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and ear ...

suse-cvrf
около 11 лет назад

Security update for Xen

github
около 4 лет назад

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

EPSS

Процентиль: 96%
0.15275
Средний

6.5 Medium

CVSS2