PT-2015-6811 · Qemu+4 · Qemu+4
Lian Yihan
·
Published
2014-08-05
·
Updated
2024-06-15
·
CVE-2015-5239
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
QEMU versions prior to 2.1.0
Description
The issue is related to an integer overflow in the VNC display driver of the QEMU emulator. This overflow can be triggered by a CLIENT CUT TEXT message, leading to an infinite loop and eventually causing the QEMU process to crash, resulting in a denial of service. The vulnerability is applicable to QEMU and affects Arista EOS when hosting guest virtual machines, particularly if untrusted users have access to the virtual machine.
Recommendations
For QEMU versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the VNC display driver or limiting the ability of users to send CLIENT CUT TEXT messages to prevent the denial of service attack.
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Arista Eos
Qemu
Suse
Ubuntu