cvelist/2015/5xxx/CVE-2015-5279.json

246 lines
10 KiB
JSON
Raw Normal View History

2017-10-16 12:31:07 -04:00
{
2023-02-02 16:00:48 +00:00
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
2019-03-17 23:29:45 +00:00
"CVE_data_meta": {
"ID": "CVE-2015-5279",
2023-02-02 16:00:48 +00:00
"ASSIGNER": "secalert@redhat.com",
2019-03-17 23:29:45 +00:00
"STATE": "PUBLIC"
},
2023-02-02 16:00:48 +00:00
"description": {
"description_data": [
{
"lang": "eng",
"value": "A heap buffer overflow flaw was found in the way QEMU's NE2000 NIC emulation implementation handled certain packets received over the network. A privileged user inside a guest could use this flaw to crash the QEMU instance (denial of service) or potentially execute arbitrary code on the host."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Heap-based Buffer Overflow",
"cweId": "CWE-122"
}
]
}
]
},
2019-03-17 23:29:45 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
2023-02-02 16:00:48 +00:00
"vendor_name": "Red Hat",
2019-03-17 23:29:45 +00:00
"product": {
"product_data": [
{
2023-02-02 16:00:48 +00:00
"product_name": "Red Hat Enterprise Linux 5",
"version": {
"version_data": [
{
"version_value": "0:83-274.el5_11",
"version_affected": "!"
},
{
"version_value": "0:3.0.3-147.el5_11",
"version_affected": "!"
}
]
}
},
{
"product_name": "Red Hat Enterprise Linux 6",
"version": {
"version_data": [
{
"version_value": "2:0.12.1.2-2.479.el6_7.2",
"version_affected": "!"
}
]
}
},
{
"product_name": "Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6",
2019-03-17 23:29:45 +00:00
"version": {
"version_data": [
{
2023-02-02 16:00:48 +00:00
"version_value": "2:0.12.1.2-2.479.el6_7.2",
"version_affected": "!"
}
]
}
},
{
"product_name": "RHEV 3.X Hypervisor and Agents for RHEL-6",
"version": {
"version_data": [
{
"version_value": "2:0.12.1.2-2.479.el6_7.2",
"version_affected": "!"
2019-03-17 23:29:45 +00:00
}
]
}
}
]
2023-02-02 16:00:48 +00:00
}
2019-03-17 23:29:45 +00:00
}
2017-10-16 12:31:07 -04:00
]
2019-03-17 23:29:45 +00:00
}
},
"references": {
"reference_data": [
{
2023-02-02 16:00:48 +00:00
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html",
"refsource": "MISC",
"name": "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html"
},
{
"url": "https://security.gentoo.org/glsa/201602-01",
"refsource": "MISC",
"name": "https://security.gentoo.org/glsa/201602-01"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html",
"refsource": "MISC",
"name": "http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.html",
"refsource": "MISC",
"name": "http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169039.html"
},
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14",
"refsource": "MISC",
"name": "https://www.arista.com/en/support/advisories-notices/security-advisories/1188-security-advisory-14"
},
{
"url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=7aa2bcad0ca837dd6d4bf4fa38a80314b4a6b755",
"refsource": "MISC",
"name": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=7aa2bcad0ca837dd6d4bf4fa38a80314b4a6b755"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169036.html",
"refsource": "MISC",
"name": "http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169036.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167369.html",
"refsource": "MISC",
"name": "http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167369.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://rhn.redhat.com/errata/RHSA-2015-1896.html",
"refsource": "MISC",
"name": "http://rhn.redhat.com/errata/RHSA-2015-1896.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://rhn.redhat.com/errata/RHSA-2015-1923.html",
"refsource": "MISC",
"name": "http://rhn.redhat.com/errata/RHSA-2015-1923.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://rhn.redhat.com/errata/RHSA-2015-1924.html",
"refsource": "MISC",
"name": "http://rhn.redhat.com/errata/RHSA-2015-1924.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://rhn.redhat.com/errata/RHSA-2015-1925.html",
"refsource": "MISC",
"name": "http://rhn.redhat.com/errata/RHSA-2015-1925.html"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://www.debian.org/security/2015/dsa-3361",
"refsource": "MISC",
"name": "http://www.debian.org/security/2015/dsa-3361"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://www.debian.org/security/2015/dsa-3362",
"refsource": "MISC",
"name": "http://www.debian.org/security/2015/dsa-3362"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://www.openwall.com/lists/oss-security/2015/09/15/3",
"refsource": "MISC",
"name": "http://www.openwall.com/lists/oss-security/2015/09/15/3"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://www.securityfocus.com/bid/76746",
"refsource": "MISC",
"name": "http://www.securityfocus.com/bid/76746"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "http://www.securitytracker.com/id/1033569",
"refsource": "MISC",
"name": "http://www.securitytracker.com/id/1033569"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "https://access.redhat.com/errata/RHSA-2015:1896",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2015:1896"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "https://access.redhat.com/errata/RHSA-2015:1923",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2015:1923"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "https://access.redhat.com/errata/RHSA-2015:1924",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2015:1924"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "https://access.redhat.com/errata/RHSA-2015:1925",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2015:1925"
2019-03-17 23:29:45 +00:00
},
{
2023-02-02 16:00:48 +00:00
"url": "https://access.redhat.com/errata/RHSA-2015:2065",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2015:2065"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2015-5279",
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/CVE-2015-5279"
},
{
2023-02-02 16:00:48 +00:00
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1256672",
"refsource": "MISC",
2023-02-02 16:00:48 +00:00
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1256672"
},
{
"url": "https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg03984.html",
"refsource": "MISC",
"name": "https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg03984.html"
}
]
},
"impact": {
"cvss": [
{
"accessComplexity": "HIGH",
"accessVector": "ADJACENT_NETWORK",
"authentication": "SINGLE",
"availabilityImpact": "COMPLETE",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 6.5,
"collateralDamagePotential": "NOT_DEFINED",
"confidentialityImpact": "COMPLETE",
"confidentialityRequirement": "NOT_DEFINED",
"environmentalScore": 0,
"exploitability": "NOT_DEFINED",
"integrityImpact": "COMPLETE",
"integrityRequirement": "NOT_DEFINED",
"remediationLevel": "NOT_DEFINED",
"reportConfidence": "NOT_DEFINED",
"targetDistribution": "NOT_DEFINED",
"temporalScore": 0,
"vectorString": "AV:A/AC:H/Au:S/C:C/I:C/A:C",
"version": "2.0"
2019-03-17 23:29:45 +00:00
}
]
}
}