CVE-2015-5154
12.08.2015, 14:59
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xen | xen | 𝑥 ≤ 4.5.0 |
| xen | xen | 4.5.1 |
| qemu | qemu | 𝑥 ≤ 2.3.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||||||||
| xen |
|
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| qemu |
| ||||||||
| qemu-kvm |
| ||||||||
| xen |
|
Common Weakness Enumeration
References