QEMU: Arbitrary code execution A heap-based buffer overflow in QEMU could result in execution of arbitrary code. qemu 2015-10-31 2015-10-31 551752 555680 556050 556052 local, remote 2.3.0-r4 2.3.0-r4

QEMU is a generic and open source machine emulator and virtualizer.

Heap-based buffer overflow has been found in QEMU’s PCNET controller.

A remote attacker could execute arbitrary code via a specially crafted packets.

There is no known workaround at this time.

All QEMU users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/qemu-2.3.0-r4"
CVE-2015-3209 CVE-2015-3214 CVE-2015-5154 CVE-2015-5158 BlueKnight Zlogene