CVE-2015-5745: Buffer Overflow
Buffer overflow in the sendcontrolmsg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-5745?
CVE-2015-5745 is a buffer overflow vulnerability in the send_control_msg function in QEMU before version 2.4.0.
What is the severity of CVE-2015-5745?
The severity of CVE-2015-5745 is medium, with a CVSS score of 6.5.
How does CVE-2015-5745 affect QEMU?
CVE-2015-5745 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message in QEMU versions before 2.4.0.
How do I fix CVE-2015-5745?
To fix CVE-2015-5745, update QEMU to version 2.4.0 or later.
Are there any references for CVE-2015-5745?
Yes, you can find more information about CVE-2015-5745 at the following links: [link1](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.html), [link2](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.html), [link3](http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.html)