CVE-2015-5154 PUBLISHED

Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.

EPSS 0.39% · 59.7th percentile

Risk Scores

EPSS Score
0.39%
59.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSqemu0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6
Ubuntu:14.04:LTSxen0, 4.3.0-1ubuntu1, 4.3.0-1ubuntu2

Timeline

References

Open in Interactive Console →