cbcvebase.
CVE-2015-5154
published 2015-08-12

CVE-2015-5154: Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest…

high7.2CVSS 3.1
AVLACLAuNCCICAC
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
debianxen< qemu 1:2.4+dfsg-1a (bookworm)qemu 1:2.4+dfsg-1a (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
qemuqemu<= 2.3.0
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 1:2.4+dfsg-1a1:2.4+dfsg-1a
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.152.0.0+dfsg-2ubuntu1.15
suselinux_enterprise_debuginfo
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_software_development_kit
susesuse_linux_enterprise_server
xenxen<= 4.5.0
xenxen
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1

CVSS provenance

nvd7.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH