cbcvebase.
CVE-2015-4037
published 2015-08-26

CVE-2015-4037: The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of…

PriorityP48low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.37%
29.3th percentile
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:2.3+dfsg-5 (bookworm)qemu 1:2.3+dfsg-5 (bookworm)
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5
qemuqemu>= 0 < 1:2.3+dfsg-51:2.3+dfsg-5
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.132.0.0+dfsg-2ubuntu1.13

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.5MEDIUM
vendor_debian1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.