CVE-2015-3209 PUBLISHED

Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.

EPSS 20.57% · 95.5th percentile

Risk Scores

EPSS Score
20.57%
95.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSqemu0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6
Ubuntu:14.04:LTSxen4.3.0-1ubuntu1, 4.3.0-1ubuntu2, 4.3.0-1ubuntu3

Timeline

References

Open in Interactive Console →