CVE-2012-3515
Publication date 6 September 2012
Last updated 24 July 2024
Ubuntu priority
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a “device model’s address space.”
Status
Package | Ubuntu Release | Status |
---|---|---|
qemu-kvm | 13.10 saucy | Not in release |
13.04 raring | Not in release | |
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Fixed 1.0+noroms-0ubuntu14.2
|
|
11.10 oneiric |
Fixed 0.14.1+noroms-0ubuntu6.5
|
|
11.04 natty |
Fixed 0.14.0+noroms-0ubuntu4.7
|
|
10.04 LTS lucid |
Fixed 0.12.3+noroms-0ubuntu9.20
|
|
8.04 LTS hardy | Not in release | |
xen | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Fixed 4.1.2-2ubuntu2.4
|
|
11.10 oneiric |
Fixed 4.1.1-2ubuntu4.4
|
|
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
xen-3.1 | 13.10 saucy | Not in release |
13.04 raring | Not in release | |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
xen-3.2 | 13.10 saucy | Not in release |
13.04 raring | Not in release | |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
xen-3.3 | 13.10 saucy | Not in release |
13.04 raring | Not in release | |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release | |
xen-qemu-dm-4.0 | 13.10 saucy | Not in release |
13.04 raring | Not in release | |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Ignored | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
qemu-kvm | |
xen-qemu-dm-4.0 |
References
Related Ubuntu Security Notices (USN)
- USN-1590-1
- QEMU vulnerability
- 2 October 2012