All errata/sisyphus/ALT-PU-2015-1439-1
ALT-PU-2015-1439-1

Package update qemu in branch sisyphus

Version2.3.0-alt2
Published2015-05-14
Max severityHIGH
Severity:

Closed issues (1)

CVE-2015-3456
HIGH7.7

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

Published: 2015-05-13Modified: 2025-04-12
CVSS 2.0HIGH 7.7
CVSS:2.0/AV:A/AC:L/Au:S/C:C/I:C/A:C
References