First published: Thu Jan 23 2020(Updated: )
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | <2.4.0.1 | |
Fedoraproject Fedora | =21 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =15.04 | |
Arista EOS | =4.12 | |
Arista EOS | =4.13 | |
Arista EOS | =4.14 | |
Arista EOS | =4.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-5278 is medium with a severity value of 6.5.
CVE-2015-5278 affects QEMU before version 2.4.0.1.
CVE-2015-5278 affects Fedora Project Fedora versions 21, 22, and 23.
CVE-2015-5278 affects Canonical Ubuntu Linux versions 12.04, 14.04, and 15.04.
The Common Weakness Enumeration (CWE) ID for CVE-2015-5278 is 835.