Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-3456

Published: 13 May 2015

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

Notes

AuthorNote
mdeslaur
See https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/VENOM

Priority

High

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
precise Does not exist

trusty
Released (2.0.0+dfsg-2ubuntu1.11)
upstream Needs triage

utopic
Released (2.1+dfsg-4ubuntu6.6)
vivid
Released (1:2.2+dfsg-5expubuntu9.1)
qemu-kvm
Launchpad, Ubuntu, Debian
precise
Released (1.0+noroms-0ubuntu14.22)
trusty Does not exist

upstream Needs triage

utopic Does not exist

vivid Does not exist

virtualbox
Launchpad, Ubuntu, Debian
precise
Released (4.1.12-dfsg-2ubuntu0.10)
trusty
Released (4.3.10-dfsg-1ubuntu5)
upstream Needs triage

utopic
Released (4.3.18-dfsg-2ubuntu3)
vivid
Released (4.3.26-dfsg-2ubuntu2)
xen
Launchpad, Ubuntu, Debian
lucid Does not exist

precise
Released (4.1.6.1-0ubuntu0.12.04.6)
trusty
Released (4.4.1-0ubuntu0.14.04.6)
upstream Needs triage

utopic
Released (4.4.1-0ubuntu0.14.10.6)
vivid Not vulnerable

Binaries built from this source package are in Universe and so are supported by the community.