PT-2015-6237 · Xen+9 · Xen+9

Marcus Meissner

·

Published

2013-11-29

·

Updated

2024-06-15

·

CVE-2015-3456

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QEMU versions prior to the fixed version Xen versions 4.5.x and earlier KVM (affected versions not specified) Check Point GAiA (affected versions not specified) Arista EOS (affected versions not specified)
Description The issue allows local guest users to cause a denial of service or possibly execute arbitrary code via certain commands, including FD CMD READ ID and FD CMD DRIVE SPECIFICATION COMMAND. A privileged guest user could use this flaw to potentially execute arbitrary code on the host of the VM. The vulnerability affects the Floppy Disk Controller emulation in QEMU.
Recommendations For QEMU, update to a version that includes the fix for this issue. For Xen, update to a version later than 4.5.x. For KVM, apply the necessary patch or update to a version that includes the fix. For Check Point GAiA, apply the recommended patch or update. For Arista EOS, ensure that untrusted users do not have access to virtual machines hosted on EOS, and consider disabling the virtual machine hosting feature until a patch is available. As a temporary workaround, restrict access to the virtual machine hosted on EOS to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1219
ALT-PU-2014-1526
ALT-PU-2014-2465
ALT-PU-2015-1412
ALT-PU-2015-1439
ALT-PU-2015-1542
ALT-PU-2015-1865
CESA-2014_0927
CESA-2014_1075
CESA-2014_1669
CESA-2015_0998
CESA-2015_0999
CESA-2015_1087
CESA-2015_1507
CESA-2015_1924
CESA-2015_1943
CESA-2016_0082
CESA-2016_0083
CVE-2015-3456
DLA-248-1
DLA-249-1
DLA-268-1
DSA-3259-1
DSA-3262-1
DSA-3274-1
ELSA-2015-0998
ELSA-2015-0999
MGASA-2015-0220
MGASA-2015-0228
MGASA-2016-0098
OPENSUSE-SU-2015_0893-1
OPENSUSE-SU-2015_0894-1
OPENSUSE-SU-2015_0983-1
OPENSUSE-SU-2015_1092-1
OPENSUSE-SU-2024:10020-1
OPENSUSE-SU-2024:10196-1
OPENSUSE-SU-2024:10233-1
RHSA-2014_0927
RHSA-2014_1075
RHSA-2014_1669
RHSA-2015:0998
RHSA-2015:0999
RHSA-2015:1000
RHSA-2015:1001
RHSA-2015:1002
RHSA-2015:1003
RHSA-2015:1004
RHSA-2015:1011
RHSA-2015:1031
RHSA-2015_0998
RHSA-2015_0999
RHSA-2015_1002
RHSA-2015_1003
RHSA-2015_1087
RHSA-2015_1189
RHSA-2015_1507
RHSA-2015_1924
RHSA-2015_1925
RHSA-2015_1943
RHSA-2015_2065
RHSA-2016_0082
RHSA-2016_0083
RHSA-2016_0450
SUSE-SU-2015:0870-1
SUSE-SU-2015:0889-1
SUSE-SU-2015:0896-1
SUSE-SU-2015:0923-1
SUSE-SU-2015:0927-1
SUSE-SU-2015:0929-1
SUSE-SU-2015:0940-1
SUSE-SU-2015:0943-1
SUSE-SU-2015:0944-1
SUSE-SU-2015:1152-1
SUSE-SU-2015_0889-1
SUSE-SU-2015_0889-2
SUSE-SU-2015_0896-1
SUSE-SU-2015_0923-1
SUSE-SU-2015_0943-1
USN-2608-1

Affected Products

Alt Linux
Arista Eos
Centos
Check Point Gaia
Kvm
Qemu
Red Hat
Suse
Ubuntu
Xen