← Back

CVE-2015-5261

nvd nist
Published: Jun 7, 2016Modified: May 6, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

Affected (16)

Show all products
1 product
Ubuntu Linux
6 products
Enterprise Linux Desktop
Enterprise Linux Hpc Node
Enterprise Linux Server
Enterprise Linux Server Eus
Enterprise Linux Workstation
Enterprise Linux Hpc Node Eus
1 product
Debian Linux
1 product
Spice
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 15.04
Configuration B
5 vulnerable
Configuration C
6 vulnerable
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.12.5

References (20)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.