--- security/vuxml/vuln.xml (revision 387127) +++ security/vuxml/vuln.xml (working copy) @@ -57,6 +57,42 @@ --> + + virtualbox-ose -- buffer overflow vulnerability in QEMU's virtual Floppy Disk Controller (FDC) + + + virtualbox-ose + 4.3.28 + + + + +

Oracle reports:

+
+

This Security Alert addresses security issue CVE-2015-3456 + ("VENOM"), a buffer overflow vulnerability in QEMU's virtual Floppy + Disk Controller (FDC). The vulnerable FDC code is included in + various virtualization platforms and is used in some Oracle products. + The vulnerability may be exploitable by an attacker who has access + to an account on the guest operating system with privilege to access + the FDC. The attacker may be able to send malicious code to the FDC + that is executed in the context of the hypervisor process on the host + operating system. This vulnerability is not remotely exploitable + without authentication, i.e., may not be exploited over a network + without the need for a username and password.

+
+ +
+ + http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html + CVE-2015-3456 + + + 2015-05-15 + 2015-05-23 + +
+ dnsmasq -- remotely exploitable buffer overflow in release candidate