Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5260

Опубликовано: 08 сент. 2015
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

A heap-based buffer overflow flaw was found in the way spice handled certain QXL commands related to the "surface_id" parameter. A user in a guest could use this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1260822spice: insufficient validation of surface_id parameter can cause crash

EPSS

Процентиль: 52%
0.00291
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

CVSS3: 7.8
nvd
около 9 лет назад

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

CVSS3: 7.8
debian
около 9 лет назад

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS user ...

CVSS3: 7.8
github
больше 3 лет назад

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

oracle-oval
почти 10 лет назад

ELSA-2015-1890: spice security update (IMPORTANT)

EPSS

Процентиль: 52%
0.00291
Низкий

5.8 Medium

CVSS2