VulnerabilityModified
CVE-2015-5239
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
MEDIUM 6.5EPSS 3.61%
Does this matter?
Lower severity and a low EPSS score (3.61%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.61% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- qemu/qemu · fedoraproject/fedora · canonical/ubuntu linux · suse/linux enterprise debuginfo · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · arista/eos
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/09/02/7Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2745-1Patch, Third Party Advisory
- https://github.com/qemu/qemu/commit/f9a70e79391f6d7c2a912d785239ee8effc1922dPatch, Third Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168077.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168646.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168671.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.htmlMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/09/02/7Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2745-1Patch, Third Party Advisory
- https://github.com/qemu/qemu/commit/f9a70e79391f6d7c2a912d785239ee8effc1922dPatch, Third Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.