PT-2015-6237 · Xen+9 · Xen+9
Marcus Meissner
·
Published
2013-11-29
·
Updated
2024-06-15
·
CVE-2015-3456
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to the fixed version
Xen versions 4.5.x and earlier
KVM (affected versions not specified)
Check Point GAiA (affected versions not specified)
Arista EOS (affected versions not specified)
Description
The issue allows local guest users to cause a denial of service or possibly execute arbitrary code via certain commands, including
FD CMD READ ID and FD CMD DRIVE SPECIFICATION COMMAND. A privileged guest user could use this flaw to potentially execute arbitrary code on the host of the VM. The vulnerability affects the Floppy Disk Controller emulation in QEMU.Recommendations
For QEMU, update to a version that includes the fix for this issue.
For Xen, update to a version later than 4.5.x.
For KVM, apply the necessary patch or update to a version that includes the fix.
For Check Point GAiA, apply the recommended patch or update.
For Arista EOS, ensure that untrusted users do not have access to virtual machines hosted on EOS, and consider disabling the virtual machine hosting feature until a patch is available. As a temporary workaround, restrict access to the virtual machine hosted on EOS to minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Arista Eos
Centos
Check Point Gaia
Kvm
Qemu
Red Hat
Suse
Ubuntu
Xen