PT-2015-1942 · Qemu Team+6 · Qemu+6

Matt Tait

·

Publicado

2015-06-17

·

Atualizado

2023-02-13

·

CVE-2015-3214

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.3.1 Linux kernel versions prior to 2.6.33
Description The issue is caused by a buffer overflow in the pit ioport read function of the QEMU emulator, which does not properly distinguish between read lengths and write lengths. This could allow a local attacker to execute arbitrary code on the host operating system by triggering the use of an invalid index. The vulnerability can be exploited by guest OS users, potentially leading to the execution of arbitrary code on the host OS.
Recommendations For QEMU versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. For Linux kernel versions prior to 2.6.33, update to version 2.6.33 or later to resolve the issue. As a temporary workaround, consider restricting access to virtual machines hosted on affected systems to trusted users only, and avoid allowing untrusted users to access the virtual machine.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1865
BDU:2015-11288
CESA-2015_1507
CVE-2015-3214
DSA-3348-1
MGASA-2015-0310
RHSA-2015:1507
RHSA-2015:1508
RHSA-2015:1512
RHSA-2015_1507
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1785-1
USN-2692-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Qemu
Red Hat
Suse
Ubuntu