CVE-2015-3209: Buffer Overflow
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUSSTARTPACKET set and then a crafted packet with TXSTATUSDEVICEOWNS set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3209?
CVE-2015-3209 has a high severity level due to the heap-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code.
How do I fix CVE-2015-3209?
To fix CVE-2015-3209, update QEMU to version 2.3.2 or later and ensure all affected systems are patched.
Which versions of software are affected by CVE-2015-3209?
CVE-2015-3209 affects QEMU versions up to 2.3.1, Juniper Networks Junos Space up to version 15.1, and several versions of Ubuntu and Red Hat Enterprise Linux.
Can CVE-2015-3209 be exploited remotely?
Yes, CVE-2015-3209 can be exploited remotely by attackers sending specially crafted packets to the vulnerable systems.
What types of systems are vulnerable to CVE-2015-3209?
Vulnerable systems include various distributions of Linux such as Ubuntu, Debian, and Red Hat Enterprise Linux, as well as certain network devices running affected versions of Juniper and QEMU.