CVE-2012-3515: Input Validation
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3515?
CVE-2012-3515 has a high severity rating due to the potential privilege escalation for local OS guest users.
How do I fix CVE-2012-3515?
To mitigate CVE-2012-3515, users should upgrade the affected QEMU version to 1.2.0 or higher.
Who is affected by CVE-2012-3515?
CVE-2012-3515 affects systems utilizing QEMU versions prior to 1.2.0 and specific versions of Xen and openSUSE.
What systems are vulnerable to CVE-2012-3515?
Vulnerable systems include Xen 4.0, 4.1 and various versions of openSUSE, SUSE Linux Enterprise, Red Hat, and Debian.
What type of vulnerability is CVE-2012-3515?
CVE-2012-3515 is a privilege escalation vulnerability that arises from improper handling of escape VT100 sequences.