Buffer overflow in Xen - CVE-2015-3456

 

Buffer overflow in Xen - CVE-2015-3456

Published: February 1, 2017 / Updated: March 10, 2017


Vulnerability identifier: #VU5580
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3456
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to buffer overflow in the Floppy Disk Controller (FDC) emulation. A remote attacker can send specially crafted FDC commands, trigger memory corruption and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in full control of the vulnerable system.

Note: the vulnerability was being actively exploited.


Affected software

Xen
Red Hat Virtualization
Debian Linux
Arch Linux
HPE Helion Openstack
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Junos OS
Helion CloudSystem
qemu (Alpine package)
xen (Alpine package)
qemu
xen
IBM Systems Director

How to mitigate CVE-2015-3456

Install update from vendor's website.

HPE Helion Openstack - update to 1.1.1
qemu (Alpine package) - update to 1.4.2-r2
xen (Alpine package) - update to 4.4.2-r1
Junos OS - addressed in versions 13.2X51-D40, 14.1X53-D30, 18.4R2-S10, 18.4R3-S10, 19.1R3-S7, 19.1R3-S9, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.3R3-S6, 19.4R2-S6, 19.4R2-S7, 19.4R3-S6, 19.4R3-S9, 20.1R3-S3, 20.1R3-S4, 20.2R3-S3, 20.2R3-S5, 20.3R3-S3, 20.3R3-S4, 20.4R3, 20.4R3-S4, 21.1R2, 21.1R3-S3, 21.2R1, 21.2R3-S1, 21.3R3-S1, 21.4R2, 22.1R2, 22.2R1
qemu - addressed in versions 2.0.0-1.el7.5, 2.1.3-7.fc21, 2.3.0-4.fc22
xen - addressed in versions 4.4.2-4.fc21, 4.5.0-9.fc22

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins