Security Advisory

CVE-2015-5154

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2015-08-12 14:00:00
Last updated 2024-08-06 06:32:32
Assigner redhat
State PUBLISHED

Description

Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.