PT-2015-1324 · Qemu+5 · Qemu+5

Matt Tait

·

Published

2015-06-03

·

Updated

2023-02-13

·

CVE-2015-3209

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description The issue is caused by a heap-based buffer overflow in the PCNET controller. Exploitation of this issue may allow a remote attacker to execute arbitrary code by sending a packet with TXSTATUS STARTPACKET set and then a crafted packet with TXSTATUS DEVICEOWNS set. This vulnerability can be exploited if a virtual machine is configured and running, and untrusted users have access to the virtual machine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1542
ALT-PU-2015-1865
BDU:2015-10394
BDU:2015-10395
CESA-2015_1087
CVE-2015-3209
DSA-3284-1
DSA-3285-1
DSA-3286-1
MGASA-2015-0310
MGASA-2016-0098
OPENSUSE-SU-2015_1092-1
OPENSUSE-SU-2015_1094-1
RHSA-2015:1087
RHSA-2015:1088
RHSA-2015:1089
RHSA-2015:1189
RHSA-2015_1087
RHSA-2015_1189
SUSE-SU-2015:0870-1
SUSE-SU-2015:0889-1
SUSE-SU-2015:0929-1
SUSE-SU-2015:1042-1
SUSE-SU-2015:1045-1
SUSE-SU-2015:1152-1
SUSE-SU-2015:1156-1
SUSE-SU-2015:1157-1
SUSE-SU-2015:1426-1
SUSE-SU-2015:1519-1
SUSE-SU-2015_1042-1
SUSE-SU-2015_1045-1
SUSE-SU-2015_1152-1
SUSE-SU-2015_1156-1
SUSE-SU-2015_1157-1
SUSE-SU-2015_1206-1
SUSE-SU-2015_1426-1
SUSE-SU-2015_1519-1
SUSE-SU-2015_1643-1
USN-2630-1

Affected Products

Alt Linux
Centos
Qemu
Red Hat
Suse
Ubuntu