QEMU 'hw/ide/core. c' Denial of Service Vulnerability (CVE-2015-6855)
QEMU 'hw/ide/core. c' Denial of Service Vulnerability (CVE-2015-6855)
Release date:
Updated on:
Affected Systems:
QEMU
Description:
Bugtraq id: 76691
CVE (CAN) ID: CVE-2015-6855
QEMU is an open source simulator software.
A single-byte overflow vulnerability exists in the QEMU simulator that supports IDE disks and CD/DVD-ROM simulation. This vulnerability is triggered when the WIN_READ_NATIVE_MAX command of IDE is executed to determine the maximum drive value, privileged users in the client will use this vulnerability to crash the QEMU instance, resulting in DOS.
<* Source: John Snow
*>
Suggestion:
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg02479.html
Linux getting started Tutorial: QEMU for Virtual Machine experience
Ubuntu 12.04 cannot find the Qemu command
Install QEMU + efi bios on Arch Linux
QEMU translation framework and debugging tools
QEMU code analysis: BIOS loading process
QEMU details: click here
QEMU: click here
This article permanently updates the link address: