Lucene search

K
f5F5F5:K17057
HistoryAug 03, 2015 - 12:00 a.m.

K17057 : QEMU vulnerabilities CVE-2015-3214, CVE-2015-5154, and CVE-2015-5158

2015-08-0300:00:00
my.f5.com
10

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

41.8%

Security Advisory Description

An out-of-bounds memory access flaw, leading to memory corruption or possibly an information leak, was found in QEMU’s pit_ioport_read() function. A privileged guest user in a QEMU guest, which had QEMU PIT emulation enabled, could potentially, in rare cases, use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process.

A heap buffer overflow flaw was found in the way QEMU’s IDE subsystem handled I/O buffer access while processing certain ATAPI commands. A privileged guest user in a guest with the CDROM drive enabled could potentially use this flaw to execute arbitrary code on the host with the privileges of the host’s QEMU process corresponding to the guest.

Qemu emulator built with the SCSI device emulation support is vulnerable to a stack buffer overflow issue. It could occur while parsing SCSI command descriptor block with an invalid operation code.

Impact

None. F5 products are not affected by this vulnerability.