1.9
CVSSv2

CVE-2015-4037

Published: 26/08/2015 Updated: 24/12/2016
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The slirp_smb function in net/slirp.c in QEMU 2.3.0 and previous versions creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

Vendor Advisories

Several security issues were fixed in QEMU ...
Debian Bug report logs - #787547 CVE-2015-4103 CVE-2015-4104 CVE-2015-4105 CVE-2015-4106 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 2 Jun 2015 17:03:01 UTC Severity: grave Tags: fixed-upstream, p ...
Debian Bug report logs - #788460 qemu: CVE-2015-3209: heap overflow in QEMU PCNET controller (allowing guest->host escape) Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 11 Jun 2015 16:09:02 UT ...