CVE-2015-5154: Buffer Overflow
Published Aug 12, 2015
·Updated
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
Affected Software
13 affected components
XEN Xen<=4.5.0
XEN Xen=4.5.1
SUSE Linux Enterprise Debuginfo=11-sp4
SUSE Linux Enterprise Desktop=11-sp4
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE SUSE Linux Enterprise Server=12
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Qemu Qemu<=2.3.0
Remediation
Patch Available
Event History
Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5154?
CVE-2015-5154 has a high severity rating due to its potential for local guest users to execute arbitrary code on the host.
2
How do I fix CVE-2015-5154?
To fix CVE-2015-5154, you should update your QEMU and Xen to the latest versions that address this vulnerability.
3
What systems are affected by CVE-2015-5154?
CVE-2015-5154 affects several versions of Xen and QEMU, including Xen 4.5.x and earlier and QEMU up to version 2.3.0.
4
What type of vulnerability is CVE-2015-5154?
CVE-2015-5154 is classified as a heap-based buffer overflow vulnerability.
5
Can CVE-2015-5154 be exploited remotely?
No, CVE-2015-5154 requires local guest user access to be exploited.