~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2015-5225

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2015-08-25
2
 
Candidate: CVE-2015-5225
3
 
PublicDate: 2015-11-06
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5225
6
 
 https://usn.ubuntu.com/usn/usn-2724-1
7
 
Description:
8
 
 Buffer overflow in the vnc_refresh_server_surface function in the VNC
9
 
 display driver in QEMU before 2.4.0.1 allows guest users to cause a denial
10
 
 of service (heap memory corruption and process crash) or possibly execute
11
 
 arbitrary code on the host via unspecified vectors, related to refreshing
12
 
 the server display surface.
13
 
Ubuntu-Description: 
14
 
Notes: 
15
 
 mdeslaur> introduced by:
16
 
 mdeslaur> http://git.qemu.org/?p=qemu.git;a=commit;h=bea60dd7679364493a0d7f5b
17
 
 mdeslaur> so precise and trusty are not affected
18
 
Bugs: 
19
 
 https://bugzilla.redhat.com/show_bug.cgi?id=1255896
20
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796465
21
 
Priority: medium
22
 
Discovered-by: Qinghao Tang and Mr. Zuozhi
23
 
Assigned-to: mdeslaur
24
 
 
25
 
Patches_qemu-kvm:
26
 
upstream_qemu-kvm: needs-triage
27
 
precise_qemu-kvm: not-affected (code not present)
28
 
trusty_qemu-kvm: DNE
29
 
vivid_qemu-kvm: DNE
30
 
devel_qemu-kvm: DNE
31
 
 
32
 
Patches_qemu:
33
 
 other: https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html
34
 
upstream_qemu: needs-triage
35
 
precise_qemu: DNE
36
 
trusty_qemu: not-affected (code not present)
37
 
vivid_qemu: released (1:2.2+dfsg-5expubuntu9.4)
38
 
devel_qemu: released (1:2.3+dfsg-5ubuntu4)