PT-2015-6811 · Qemu+4 · Qemu+4

Lian Yihan

·

Published

2014-08-05

·

Updated

2024-06-15

·

CVE-2015-5239

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions prior to 2.1.0
Description The issue is related to an integer overflow in the VNC display driver of the QEMU emulator. This overflow can be triggered by a CLIENT CUT TEXT message, leading to an infinite loop and eventually causing the QEMU process to crash, resulting in a denial of service. The vulnerability is applicable to QEMU and affects Arista EOS when hosting guest virtual machines, particularly if untrusted users have access to the virtual machine.
Recommendations For QEMU versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the VNC display driver or limiting the ability of users to send CLIENT CUT TEXT messages to prevent the denial of service attack.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1987
CVE-2015-5239
DLA-573-1
DLA-574-1
MGASA-2015-0368
OPENSUSE-SU-2015_1964-1
OPENSUSE-SU-2015_2003-1
OPENSUSE-SU-2016_0995-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:1853-1
SUSE-SU-2015:1894-1
SUSE-SU-2015:1908-1
SUSE-SU-2015:1952-1
SUSE-SU-2015:2324-1
SUSE-SU-2016:1560-1
SUSE-SU-2016:1698-1
SUSE-SU-2016:1785-1
USN-2745-1

Affected Products

Alt Linux
Arista Eos
Qemu
Suse
Ubuntu