All errata/p7/ALT-PU-2015-1447-1
ALT-PU-2015-1447-1

Package update qemu in branch p7

Version1.4.0-alt1.1.M70P.1
Published2015-05-15
Max severityHIGH
Severity:

Closed issues (1)

CVE-2015-3456
HIGH7.7

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

Published: 2015-05-13Modified: 2025-04-12
CVSS 2.0HIGH 7.7
CVSS:2.0/AV:A/AC:L/Au:S/C:C/I:C/A:C
References