cbcvebase.
CVE-2015-3209
published 2015-06-15

CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos
aristaeos
aristaeos
aristaeos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianqemu< qemu 1:2.3+dfsg-6 (bookworm)qemu 1:2.3+dfsg-6 (bookworm)
debianxen< qemu 1:2.3+dfsg-6 (bookworm)qemu 1:2.3+dfsg-6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
juniperjunos_space<= 15.1
qemuqemu<= 2.3.1
qemuqemu>= 0 < 1:2.3+dfsg-61:2.3+dfsg-6
qemuqemu>= 0 < 1:2.3+dfsg-61:2.3+dfsg-6
qemuqemu>= 0 < 1:2.3+dfsg-61:2.3+dfsg-6
qemuqemu>= 0 < 1:2.3+dfsg-61:2.3+dfsg-6
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.132.0.0+dfsg-2ubuntu1.13
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH