cbcvebase.
CVE-2015-3456
published 2015-05-13

CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write…

high7.7CVSS 3.1
AVAACLAuSCCICAC
EXPLOIT
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:2.3+dfsg-3 (bookworm)qemu 1:2.3+dfsg-3 (bookworm)
debianvirtualbox< qemu 1:2.3+dfsg-3 (bookworm)qemu 1:2.3+dfsg-3 (bookworm)
debianxen< qemu 1:2.3+dfsg-3 (bookworm)qemu 1:2.3+dfsg-3 (bookworm)
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.3+dfsg-31:2.3+dfsg-3
qemuqemu>= 0 < 1:2.3+dfsg-31:2.3+dfsg-3
qemuqemu>= 0 < 1:2.3+dfsg-31:2.3+dfsg-3
qemuqemu>= 0 < 1:2.3+dfsg-31:2.3+dfsg-3
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.112.0.0+dfsg-2ubuntu1.11
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_virtualization
redhatopenstack
redhatopenstack
redhatopenstack
redhatopenstack
xenxen
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1

CVSS provenance

nvd7.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
osv8.6HIGH