UBUNTU-CVE-2015-8613
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-8613
UBUNTU-CVE-2015-8613
Summary:
Details: Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.
References: https://ubuntu.com/security/CVE-2015-8613, https://lists.gnu.org/archive/html/qemu-devel/2015-12/msg03737.html, https://bugzilla.redhat.com/show_bug.cgi?id=1284008, http://www.openwall.com/lists/oss-security/2015/12/21/7, https://ubuntu.com/security/notices/USN-2891-1, https://www.cve.org/CVERecord?id=CVE-2015-8613
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.22?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
