CVE-2012-3515
published 2012-11-23CVE-2012-3515: Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.1th percentile
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 1.1.2+dfsg-1 (bookworm) | qemu 1.1.2+dfsg-1 (bookworm) |
| debian | xen | < qemu 1.1.2+dfsg-1 (bookworm) | qemu 1.1.2+dfsg-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | < 1.2.0 | 1.2.0 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-1 | 1.1.2+dfsg-1 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-1 | 1.1.2+dfsg-1 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-1 | 1.1.2+dfsg-1 |
| qemu | qemu | >= 0 < 1.1.2+dfsg-1 | 1.1.2+dfsg-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerability
vendor_ubuntu·2012-10-02
CVE-2012-3515 QEMU vulnerability
Title: QEMU vulnerability
Summary: QEMU could be made to crash or run programs.
It was discovered that QEMU incorrectly handled certain VT100 escape
sequences. A guest user with access to an emulated character device could
use this flaw to cause QEMU to crash, or possibly execute arbitrary code on
the host.
Instructions: After a standard system update you need to restart your virtual machines to
make all the necessary changes.
Red Hat
qemu: VT100 emulation vulnerability
vendor_redhat·2012-09-05·CVSS 7.2
CVE-2012-3515 [HIGH] CWE-839 qemu: VT100 emulation vulnerability
qemu: VT100 emulation vulnerability
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Statement: This issue did affect the versions of xen package as shipped with Red Hat
Enterprise Linux 5.
This issue did affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue did affect the versions of qemu-kvm package as shipped with Red Hat
Enterprise Linux 6.
Package: kvm (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2012-3515: qemu - Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certai...
vendor_debian·2012·CVSS 7.2
CVE-2012-3515 [HIGH] CVE-2012-3515: qemu - Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certai...
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-1)
bullseye: resolved (fixed in 1.1.2+dfsg-1)
forky: resolved (fixed in 1.1.2+dfsg-1)
sid: resolved (fixed in 1.1.2+dfsg-1)
trixie: resolved (fixed in 1.1.2+dfsg-1)
GHSA
GHSA-rwhm-5hjg-54j9: Qemu, as used in Xen 4
ghsa_unreviewed·2022-05-13
CVE-2012-3515 [HIGH] CWE-20 GHSA-rwhm-5hjg-54j9: Qemu, as used in Xen 4
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
OSV
CVE-2012-3515: Qemu, as used in Xen 4
osv·2012-11-23·CVSS 7.2
CVE-2012-3515 [HIGH] CVE-2012-3515: Qemu, as used in Xen 4
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
bugzilla·2012-09-05·CVSS 7.2
CVE-2012-3515 [HIGH] CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=851252
Bugzilla
CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
bugzilla·2012-09-05·CVSS 7.2
CVE-2012-3515 [HIGH] CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
CVE-2012-3515 qemu: VT100 emulation vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=851252
Bugzilla
CVE-2012-3515 qemu: VT100 emulation vulnerability
bugzilla·2012-08-23·CVSS 7.2
CVE-2012-3515 [HIGH] CVE-2012-3515 qemu: VT100 emulation vulnerability
CVE-2012-3515 qemu: VT100 emulation vulnerability
A flaw has been found in the way qemu handles VT100 escape sequences when emulating certain devices with a virtual console backend.
An attacker who has sufficient privilege to access a vulnerable device within a guest can overwrite portions qemu address space. This can allow them to escalate their privileges to that of the qemu process on the host.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Xen
===
All hosts running HVM guests are potentially vulnerable to this depending on the specific guest configuration. The default configuration is not vulnerable.
When using libvirt, the default configuration of managed guests is safe, too. Libvirt by default configures the serial and para
http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00051.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1233.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1234.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1235.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1236.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1262.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1325.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50528http://secunia.com/advisories/50530http://secunia.com/advisories/50632http://secunia.com/advisories/50689http://secunia.com/advisories/50860http://secunia.com/advisories/50913http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-17_Qemu_VT100_emulation_vulnerabilityhttp://www.debian.org/security/2012/dsa-2543http://www.debian.org/security/2012/dsa-2545http://www.openwall.com/lists/oss-security/2012/09/05/10http://www.securityfocus.com/bid/55413http://www.ubuntu.com/usn/USN-1590-1https://security.gentoo.org/glsa/201604-03http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=loghttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00051.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1233.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1234.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1235.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1236.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1262.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1325.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50528http://secunia.com/advisories/50530http://secunia.com/advisories/50632http://secunia.com/advisories/50689http://secunia.com/advisories/50860http://secunia.com/advisories/50913http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-17_Qemu_VT100_emulation_vulnerabilityhttp://www.debian.org/security/2012/dsa-2543http://www.debian.org/security/2012/dsa-2545http://www.openwall.com/lists/oss-security/2012/09/05/10http://www.securityfocus.com/bid/55413http://www.ubuntu.com/usn/USN-1590-1https://security.gentoo.org/glsa/201604-03
2012-11-23
Published