Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-6855

Опубликовано: 06 нояб. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

РелизСтатусПримечание
devel

released

1:2.3+dfsg-5ubuntu7
esm-infra-legacy/trusty

released

2.0.0+dfsg-2ubuntu1.19
precise

DNE

trusty

released

2.0.0+dfsg-2ubuntu1.19
trusty/esm

released

2.0.0+dfsg-2ubuntu1.19
upstream

needs-triage

vivid

released

1:2.2+dfsg-5expubuntu9.5

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

released

1.0+noroms-0ubuntu14.25
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid

DNE

Показывать по

EPSS

Процентиль: 88%
0.03502
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
почти 11 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

CVSS3: 7.5
nvd
почти 11 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

CVSS3: 7.5
debian
почти 11 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted ...

CVSS3: 7.5
github
больше 4 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

fstec
почти 11 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое неустановленное воздействие

EPSS

Процентиль: 88%
0.03502
Низкий

5 Medium

CVSS2

7.5 High

CVSS3