CVE-2015-5278: Medium severity qemu vulnerability
Published Jan 23, 2020
·Updated
The ne2000receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
Affected Software
11 affected components
Qemu Qemu<2.4.0.1
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Arista EOS=4.12
Arista EOS=4.13
Arista EOS=4.14
Arista EOS=4.15
Remediation
Patch Available
Event History
Jan 23, 2020
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-5278?
The severity of CVE-2015-5278 is medium with a severity value of 6.5.
2
How does CVE-2015-5278 affect QEMU?
CVE-2015-5278 affects QEMU before version 2.4.0.1.
3
How does CVE-2015-5278 affect Fedora Project Fedora?
CVE-2015-5278 affects Fedora Project Fedora versions 21, 22, and 23.
4
How does CVE-2015-5278 affect Canonical Ubuntu Linux?
CVE-2015-5278 affects Canonical Ubuntu Linux versions 12.04, 14.04, and 15.04.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-5278?
The Common Weakness Enumeration (CWE) ID for CVE-2015-5278 is 835.