CVE-2015-5239: Arista Eos
Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
Affected products
- Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
- Qemu Qemu: before 2.1.0 (fixed in 2.1.0)
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
Published 2020-01-23. Last modified 2026-06-17.