Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-5225

Published: 25 August 2015

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.

Notes

AuthorNote
mdeslaur
introduced by:
http://git.qemu.org/?p=qemu.git;a=commit;h=bea60dd7679364493a0d7f5b
so precise and trusty are not affected

Priority

Medium

Status

Package Release Status
qemu
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Not vulnerable
(code not present)
upstream Needs triage

vivid
Released (1:2.2+dfsg-5expubuntu9.4)
Patches:
other: https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html
qemu-kvm
Launchpad, Ubuntu, Debian
precise Not vulnerable
(code not present)
trusty Does not exist

upstream Needs triage

vivid Does not exist