CVE-2015-3456
published 2015-05-13CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write…
PriorityP351high7.7CVSS 2.0
AVAACLAuSCCICAC
EXPLOIT
EPSS
15.28%
96.4th percentile
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.3+dfsg-3 (bookworm) | qemu 1:2.3+dfsg-3 (bookworm) |
| debian | virtualbox | < qemu 1:2.3+dfsg-3 (bookworm) | qemu 1:2.3+dfsg-3 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-3 (bookworm) | qemu 1:2.3+dfsg-3 (bookworm) |
| qemu | qemu | <= 2.3.0 | — |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-3 | 1:2.3+dfsg-3 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.11 | 2.0.0+dfsg-2ubuntu1.11 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_virtualization | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.07.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
osv8.6HIGH
vendor_ubuntu8.6HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-05-13·CVSS 8.6
CVE-2015-1779 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Jason Geffner discovered that QEMU incorrectly handled the virtual floppy
driver. This issue is known as VENOM. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-3456)
Daniel P. Berrange discovered that QEMU incorrectly handled VNC websockets.
A remote attacker could use this issue to cause QEMU to consume memory,
resulting in a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-1779)
Jan Beulich discovered that QEMU, when
Red Hat
qemu: fdc: out-of-bounds fifo buffer memory access
vendor_redhat·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] CWE-119 qemu: fdc: out-of-bounds fifo buffer memory access
qemu: fdc: out-of-bounds fifo buffer memory access
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
An out-of-bounds memory access flaw was found in the way QEMU's virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host's QEMU process corresponding to the guest.
Statement: This issue affects the versions of the kvm and xen packag
Debian
CVE-2015-3456: qemu - The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and K...
vendor_debian·2015·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456: qemu - The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and K...
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-3)
bullseye: resolved (fixed in 1:2.3+dfsg-3)
forky: resolved (fixed in 1:2.3+dfsg-3)
sid: resolved (fixed in 1:2.3+dfsg-3)
trixie: resolved (fixed in 1:2.3+dfsg-3)
GHSA
GHSA-f822-h734-j822: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4
ghsa_unreviewed·2022-05-13
CVE-2015-3456 [HIGH] CWE-119 GHSA-f822-h734-j822: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
OSV
CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4
osv·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-05-13·CVSS 8.6
CVE-2015-3456 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Jason Geffner discovered that QEMU incorrectly handled the virtual floppy
driver. This issue is known as VENOM. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-3456)
Daniel P. Berrange discovered that QEMU incorrectly handled VNC websockets.
A remote attacker could use this issue to cause QEMU to consume memory,
resulting in a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-1779)
Jan Beulich discovered that QEMU, when used with Xen, didn't properly
restrict access to P
No detection rules found.
Qualys
Venom Hypervisor Vulnerability | Qualys
blogs_qualys·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] Venom Hypervisor Vulnerability | Qualys
Crowdstrike published details today about a critical vulnerability that they discovered in a number of virtualization hypervisors: KVM, QEMU and Xen. The vulnerability CVE-2015-3456, called “Venom” by Crowdstrike, is in the floppy disk driver. It allows the guest operating system running under the hypervisor to break out of the hypervisor and get access to the host operating system. This is one of the worst classes of vulnerabilities in virtualization, since from there the attacker can infect other guest operating systems, or try to get into other host systems in typical lateral growth fashion. There is no patch that can be applied at the guest level, i.e. the level that you typically control. The problem has to be fixed at the host level, which is typically controlled by a service provide
Tenable
VENOM Vulnerability Threatens Virtual Machines (Updated)
blogs_tenable·2015-05-13
VENOM Vulnerability Threatens Virtual Machines (Updated)
Blog /
Subscribe
# VENOM Vulnerability Threatens Virtual Machines (Updated)
Kelly Prevett
May 13, 2015
2 Min Read
Today the VENOM (Virtualized Environment Neglected Operations Manipulation) vulnerability, CVE 2015-3456, was announced. VENOM originates in a legacy virtual floppy disk controller from QEMU. If an attacker sends specially crafted code to the controller, it can crash the hypervisor and allow the attacker to break out of the VM to access other machines. VENOM impacts several popular virtualization platforms that include the QEMU controller, including Xen, KVM, and Oracle’s VirtualBox. Patches for QEMU and Xen are already available. To date, no exploit has been observed in the wild. Other virtual machine platforms such as VMware, Microsoft Hyper-V, and Bochs hypervisors are
Qualys
Venom Hypervisor Vulnerability | Qualys
blogs_qualys·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] Venom Hypervisor Vulnerability | Qualys
Crowdstrike published details today about a critical vulnerability that they discovered in a number of virtualization hypervisors: KVM, QEMU and Xen. The vulnerability CVE-2015-3456, called “Venom” by Crowdstrike, is in the floppy disk driver. It allows the guest operating system running under the hypervisor to break out of the hypervisor and get access to the host operating system. This is one of the worst classes of vulnerabilities in virtualization, since from there the attacker can infect other guest operating systems, or try to get into other host systems in typical lateral growth fashion. There is no patch that can be applied at the guest level, i.e. the level that you typically control. The problem has to be fixed at the host level, which is typically controlled by a service provide
Tenable
VENOM Vulnerability Threatens Virtual Machines (Updated)
blogs_tenable·2015-05-13
VENOM Vulnerability Threatens Virtual Machines (Updated)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
Read Article "Venom Vulnerability Details" by Editorial Team
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Read Article "Venom Vulnerability Details" by Editorial Team
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Bugzilla
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [epel-7]
bugzilla·2015-05-15·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [epel-7]
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for qemu: see blocks bug list for f
Bugzilla
CVE-2015-3456 xen: qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
bugzilla·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456 xen: qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
CVE-2015-3456 xen: qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
bugzilla·2015-05-13·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access
bugzilla·2015-05-05·CVSS 7.7
CVE-2015-3456 [HIGH] CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access
CVE-2015-3456 qemu: fdc: out-of-bounds fifo buffer memory access
An out-of-bounds memory access flaw was found in the way QEMU's virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the hosting QEMU process.
Acknowledgements:
Red Hat would like to thank Jason Geffner of CrowdStrike for reporting this issue.
Discussion:
Statement:
This issue affects the versions of the kvm and xen packages as shipped with Red Hat Enterprise Linux 5, the versions of the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6 and 7, and the versions of qemu-kvm-rhev packages as shipped with Red Hat Enterprise Virt
arXiv
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
arxiv_fulltext·2024-04-03
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
[1]Litao Li
[1]Steven H. H. Ding
[2]Andrew Walenstein
[3]Philippe Charland
[4]Benjamin C. M. Fung
[1]L1NNA Lab, School of Computing, Queen's University, Canada
[2]BlackBerry Ltd., Canada
[3]Mission Critical Cyber Security Section, Defence R&D Canada
[4]Data Mining and Security (DMaS) Lab, McGill University, Canada
## Abstract
Software vulnerabilities are a challenge in cybersecurity. Manual security patches are often difficult and slow to be deployed, while new vulnerabilities are created. Binary code vulnerability detection is less studied and more complex compared to source code, and this has important practical implications. Deep learning has become an efficient and powe
arXiv
SAFE: Self-Attentive Function Embeddings for Binary Similarity
arxiv_fulltext·2019-12-19
SAFE: Self-Attentive Function Embeddings for Binary Similarity
for Binary Similarity
Luca Massarelli^ , Giuseppe Antonio Di Luna^ , Fabio Petroni^*,
Leonardo Querzoni^ , Roberto Baldoni^
: University of Rome Sapienza. \massarelli, querzoni, baldoni\@diag.uniroma1.it.
: CINI, National Laboratory of Cyber Security. [email protected].
*: Facebook AI Research, [email protected].
## Abstract
The binary similarity problem consists in determining if two functions are similar by only considering their compiled form. Advanced techniques for binary similarity recently gained momentum as they can be applied in several fields, such as copyright disputes, malware analysis, vulnerability detection, etc., and thus have an immediate practical impact. Current solutions compare functions by first transforming their binary code in multi-dimensional vector repres
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=e907746266721f305d67bc0718795fedee2e824chttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10693http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00021.htmlhttp://marc.info/?l=bugtraq&m=143229451215900&w=2http://marc.info/?l=bugtraq&m=143387998230996&w=2http://rhn.redhat.com/errata/RHSA-2015-0998.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0999.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1001.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1002.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1011.htmlhttp://support.citrix.com/article/CTX201078http://venom.crowdstrike.com/http://www.debian.org/security/2015/dsa-3259http://www.debian.org/security/2015/dsa-3262http://www.debian.org/security/2015/dsa-3274http://www.fortiguard.com/advisory/2015-05-19-cve-2015-3456-venom-vulnerabilityhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/74640http://www.securitytracker.com/id/1032306http://www.securitytracker.com/id/1032311http://www.securitytracker.com/id/1032917http://www.ubuntu.com/usn/USN-2608-1http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-438937.htmhttp://xenbits.xen.org/xsa/advisory-133.htmlhttps://access.redhat.com/articles/1444903https://bto.bluecoat.com/security-advisory/sa95https://kb.juniper.net/JSA10783https://kc.mcafee.com/corporate/index?page=content&id=SB10118https://security.gentoo.org/glsa/201602-01https://security.gentoo.org/glsa/201604-03https://security.gentoo.org/glsa/201612-27https://securityblog.redhat.com/2015/05/13/venom-dont-get-bitten/https://support.lenovo.com/us/en/product_security/venomhttps://www.arista.com/en/support/advisories-notices/security-advisories/1128-security-advisory-10https://www.exploit-db.com/exploits/37053/https://www.suse.com/security/cve/CVE-2015-3456.htmlhttp://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=e907746266721f305d67bc0718795fedee2e824chttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10693http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00021.htmlhttp://marc.info/?l=bugtraq&m=143229451215900&w=2http://marc.info/?l=bugtraq&m=143387998230996&w=2http://rhn.redhat.com/errata/RHSA-2015-0998.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0999.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1001.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1002.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1011.htmlhttp://support.citrix.com/article/CTX201078http://venom.crowdstrike.com/http://www.debian.org/security/2015/dsa-3259http://www.debian.org/security/2015/dsa-3262http://www.debian.org/security/2015/dsa-3274http://www.fortiguard.com/advisory/2015-05-19-cve-2015-3456-venom-vulnerabilityhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/74640http://www.securitytracker.com/id/1032306http://www.securitytracker.com/id/1032311http://www.securitytracker.com/id/1032917http://www.ubuntu.com/usn/USN-2608-1http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-438937.htmhttp://xenbits.xen.org/xsa/advisory-133.htmlhttps://access.redhat.com/articles/1444903https://bto.bluecoat.com/security-advisory/sa95https://kb.juniper.net/JSA10783https://kc.mcafee.com/corporate/index?page=content&id=SB10118https://security.gentoo.org/glsa/201602-01https://security.gentoo.org/glsa/201604-03https://security.gentoo.org/glsa/201612-27https://securityblog.redhat.com/2015/05/13/venom-dont-get-bitten/https://support.lenovo.com/us/en/product_security/venomhttps://www.arista.com/en/support/advisories-notices/security-advisories/1128-security-advisory-10https://www.exploit-db.com/exploits/37053/https://www.suse.com/security/cve/CVE-2015-3456.html
2015-05-13
Published