PT-2015-1967 · Qemu+6 · Qemu+6

Kevin Wolf

·

Publicado

2015-07-17

·

Atualizado

2024-06-15

·

CVE-2015-5154

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions prior to the version that includes the fix for this issue Xen versions 4.5.x and earlier
Description The issue is related to a heap-based buffer overflow in the IDE subsystem of QEMU, which is used in Xen. This overflow can occur when the container has a CDROM drive enabled, allowing local guest users to execute arbitrary code on the host via unspecified ATAPI commands. The vulnerability can be exploited by a local attacker to gain control over the host system.
Recommendations For Xen versions 4.5.x and earlier, update to a version that includes the fix for this issue. For QEMU, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the CDROM drive in the container to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1865
BDU:2015-11313
CESA-2015_1507
CVE-2015-5154
DSA-3348-1
MGASA-2015-0310
MGASA-2016-0098
OPENSUSE-SU-2015_1964-1
OPENSUSE-SU-2015_2003-1
OPENSUSE-SU-2024:10196-1
RHSA-2015:1507
RHSA-2015:1508
RHSA-2015:1512
RHSA-2015_1507
SUSE-SU-2015:1299-1
SUSE-SU-2015:1302-1
SUSE-SU-2015:1408-1
SUSE-SU-2015:1409-1
SUSE-SU-2015:1421-1
SUSE-SU-2015:1426-1
SUSE-SU-2015:1455-1
SUSE-SU-2015:1472-1
SUSE-SU-2015:1479-1
SUSE-SU-2015:1479-2
SUSE-SU-2015:1782-1
SUSE-SU-2015:2324-1
SUSE-SU-2015_1408-1
SUSE-SU-2015_1409-1
SUSE-SU-2015_1421-1
SUSE-SU-2015_1455-1
SUSE-SU-2015_1472-1
USN-2692-1

Produtos afetados

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu
Xen