9.3

CVE-2015-5165

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xen ≫ Xen Version <= 4.5.0
Xen ≫ Xen Version 4.5.1
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Openstack Version 5.0
Redhat ≫ Openstack Version 6.0
Redhat ≫ Virtualization Version 3.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Arista ≫ Eos Version 4.12
Arista ≫ Eos Version 4.13
Arista ≫ Eos Version 4.14
Arista ≫ Eos Version 4.15
Oracle ≫ Linux Version 7 Update 0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.29% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
Third Party Advisory
Mailing List
Issue Tracking
https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
Third Party Advisory
Mailing List
Issue Tracking
http://www.debian.org/security/2015/dsa-3348
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html
Third Party Advisory
Mailing List
Issue Tracking
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html
Third Party Advisory
Mailing List
Issue Tracking
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html
Third Party Advisory
Mailing List
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1674.html
Third Party Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1683.html
Third Party Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1739.html
Third Party Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1740.html
Third Party Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1793.html
Third Party Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-1833.html
Third Party Advisory
Issue Tracking
http://support.citrix.com/article/CTX201717
Third Party Advisory
Broken Link
http://www.debian.org/security/2015/dsa-3349
Third Party Advisory
http://www.securityfocus.com/bid/76153
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033176
Third Party Advisory
VDB Entry
http://xenbits.xen.org/xsa/advisory-140.html
Patch
Vendor Advisory