CVE-2015-5225
published 2015-11-06CVE-2015-5225: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service…
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.4th percentile
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.4+dfsg-1a (bookworm) | qemu 1:2.4+dfsg-1a (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qemu | qemu | <= 2.4.0 | — |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 1:2.4+dfsg-1a | 1:2.4+dfsg-1a |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.17 | 2.0.0+dfsg-2ubuntu1.17 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xf7r-x3p2-rg72: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2
ghsa_unreviewed·2022-05-17
CVE-2015-5225 [HIGH] CWE-119 GHSA-xf7r-x3p2-rg72: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
OSV
CVE-2015-5225: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2
osv·2015-11-06·CVSS 7.2
CVE-2015-5225 [HIGH] CVE-2015-5225: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-08-27·CVSS 4.9
CVE-2014-9718 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
It was discovered that QEMU incorrectly handled a PRDT with zero complete
sectors in the IDE functionality. A malicious guest could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-9718)
Donghai Zhu discovered that QEMU incorrectly handled the RTL8139 driver.
A malicious guest could possibly use this issue to read sensitive
information from arbitrary host memory. (CVE-2015-5165)
Donghai Zhu discovered that QEMU incorrectly handled unplugging emulated
block devices. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, at
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-08-27·CVSS 4.9
CVE-2014-9718 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU incorrectly handled a PRDT with zero complete
sectors in the IDE functionality. A malicious guest could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-9718)
Donghai Zhu discovered that QEMU incorrectly handled the RTL8139 driver.
A malicious guest could possibly use this issue to read sensitive
information from arbitrary host memory. (CVE-2015-5165)
Donghai Zhu discovered that QEMU incorrectly handled unplugging emulated
block devices. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the defau
Red Hat
Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
vendor_redhat·2015-08-22·CVSS 7.2
CVE-2015-5225 [HIGH] CWE-122 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
A heap-based buffer overflow issue was found in the QEMU emulator's VNC display driver. It could occur while refreshing the VNC server's display surface using the vnc_refresh_server_surface() routine. A privileged guest user could use this flaw to corrupt the heap memory and crash the QEMU process instance, or to potentially use it to execute arbitrary code on the host.
Statement: This issue does not affe
Debian
CVE-2015-5225: qemu - Buffer overflow in the vnc_refresh_server_surface function in the VNC display dr...
vendor_debian·2015·CVSS 7.2
CVE-2015-5225 [HIGH] CVE-2015-5225: qemu - Buffer overflow in the vnc_refresh_server_surface function in the VNC display dr...
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-1a)
bullseye: resolved (fixed in 1:2.4+dfsg-1a)
forky: resolved (fixed in 1:2.4+dfsg-1a)
sid: resolved (fixed in 1:2.4+dfsg-1a)
trixie: resolved (fixed in 1:2.4+dfsg-1a)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
bugzilla·2015-08-21·CVSS 7.2
CVE-2015-5225 [HIGH] CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface
Qemu emulator built with the VNC display driver support is vulnerable to a
buffer overflow flaw leading to heap memory corruption. It could occur while
refreshing the server display surface via routine vnc_refresh_server_surface().
A privileged guest user could use this flaw to corrupt the heap memory and crash the Qemu process instance OR potentially use it to execute arbitrary code on the host.
Upstream fix:
-> https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html
Issue introduced by:
-> http://git.qemu.org/?p=qemu.git;a=commit;h=bea60dd7679364493a0d7f5b
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1255899]
---
Statement:
This issue does not affect
Bugzilla
CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface [fedora-all]
bugzilla·2015-08-21·CVSS 7.2
CVE-2015-5225 [HIGH] CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface [fedora-all]
CVE-2015-5225 Qemu: ui: vnc: heap memory corruption in vnc_refresh_server_surface [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165484.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166798.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1772.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1837.htmlhttp://www.debian.org/security/2015/dsa-3348http://www.openwall.com/lists/oss-security/2015/08/21/6http://www.securityfocus.com/bid/76506http://www.securitytracker.com/id/1033547https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2015-09/msg05832.htmlhttps://security.gentoo.org/glsa/201602-01http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165484.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166798.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1772.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1837.htmlhttp://www.debian.org/security/2015/dsa-3348http://www.openwall.com/lists/oss-security/2015/08/21/6http://www.securityfocus.com/bid/76506http://www.securitytracker.com/id/1033547https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2015-09/msg05832.htmlhttps://security.gentoo.org/glsa/201602-01
2015-11-06
Published