CVE-2015-5165
high · 9.3The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
9.3
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2015-08-12
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-908
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| xen | xen | <= 4.5.0 |
| xen | xen | 4.5.1 |
| fedoraproject | fedora | 21 |
| fedoraproject | fedora | 22 |
| suse | linux_enterprise_debuginfo | 11 |
| suse | linux_enterprise_server | 10 |
| suse | linux_enterprise_server | 11 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| redhat | openstack | 5.0 |
| redhat | openstack | 6.0 |
| redhat | virtualization | 3.0 |
| redhat | enterprise_linux_compute_node_eus | 7.1 |
| redhat | enterprise_linux_compute_node_eus | 7.2 |
| redhat | enterprise_linux_compute_node_eus | 7.3 |
| redhat | enterprise_linux_compute_node_eus | 7.4 |
| redhat | enterprise_linux_compute_node_eus | 7.5 |
| redhat | enterprise_linux_compute_node_eus | 7.6 |
| redhat | enterprise_linux_compute_node_eus | 7.7 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 6.7 |
| redhat | enterprise_linux_eus_compute_node | 6.7 |
| redhat | enterprise_linux_for_power_big_endian | 6.0 |
| redhat | enterprise_linux_for_power_big_endian | 7.0 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.7_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.1_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.2_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.3_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.4_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.5_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.6_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.7 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
- http://rhn.redhat.com/errata/RHSA-2015-1674.html
- http://rhn.redhat.com/errata/RHSA-2015-1683.html
- http://rhn.redhat.com/errata/RHSA-2015-1739.html
- http://rhn.redhat.com/errata/RHSA-2015-1740.html
- http://rhn.redhat.com/errata/RHSA-2015-1793.html
- http://rhn.redhat.com/errata/RHSA-2015-1833.html
- http://support.citrix.com/article/CTX201717
- http://www.debian.org/security/2015/dsa-3348
- http://www.debian.org/security/2015/dsa-3349
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/76153
- http://www.securitytracker.com/id/1033176
- http://xenbits.xen.org/xsa/advisory-140.html
- https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
- http://rhn.redhat.com/errata/RHSA-2015-1674.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-5165