Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-6855

Опубликовано: 06 нояб. 2015
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 7.5

Описание

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

РелизСтатусПримечание
devel

released

1:2.3+dfsg-5ubuntu7
esm-infra-legacy/trusty

released

2.0.0+dfsg-2ubuntu1.19
precise

DNE

trusty

released

2.0.0+dfsg-2ubuntu1.19
trusty/esm

released

2.0.0+dfsg-2ubuntu1.19
upstream

needs-triage

vivid

released

1:2.2+dfsg-5expubuntu9.5

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

released

1.0+noroms-0ubuntu14.25
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid

DNE

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

CVSS3: 7.5
nvd
больше 10 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

CVSS3: 7.5
debian
больше 10 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted ...

CVSS3: 7.5
github
больше 3 лет назад

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

fstec
больше 10 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое неустановленное воздействие

5 Medium

CVSS2

7.5 High

CVSS3