PT-2015-1324 · Qemu+5 · Qemu+5
Matt Tait
·
Published
2015-06-03
·
Updated
2023-02-13
·
CVE-2015-3209
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
QEMU (affected versions not specified)
Description
The issue is caused by a heap-based buffer overflow in the PCNET controller. Exploitation of this issue may allow a remote attacker to execute arbitrary code by sending a packet with
TXSTATUS STARTPACKET set and then a crafted packet with TXSTATUS DEVICEOWNS set. This vulnerability can be exploited if a virtual machine is configured and running, and untrusted users have access to the virtual machine.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu