CVE-2015-5225
Published: 25 August 2015
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
Notes
Author | Note |
---|---|
mdeslaur | introduced by: http://git.qemu.org/?p=qemu.git;a=commit;h=bea60dd7679364493a0d7f5b so precise and trusty are not affected |
Priority
Status
Package | Release | Status |
---|---|---|
qemu Launchpad, Ubuntu, Debian |
precise |
Does not exist
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Needs triage
|
|
vivid |
Released
(1:2.2+dfsg-5expubuntu9.4)
|
|
Patches: other: https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html |
||
qemu-kvm Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
(code not present)
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
vivid |
Does not exist
|