CVE-2015-3456
13.05.2015, 18:59
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.Enginsight
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 𝑥 ≤ 2.3.0 |
| redhat | enterprise_virtualization | 3.0 |
| redhat | openstack | 4.0 |
| redhat | openstack | 5.0 |
| redhat | openstack | 6.0 |
| redhat | openstack | 7.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| xen | xen | 4.5.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||
| virtualbox |
| ||||||||||
| xen |
|
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||
| qemu-kvm |
| ||||||||||
| virtualbox |
| ||||||||||
| xen |
|
Common Weakness Enumeration
References