CVE-2015-5239: Arista Eos

Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.

Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

Affected products

  • Arista Eos: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Qemu Qemu: before 2.1.0 (fixed in 2.1.0)
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only

Published 2020-01-23. Last modified 2026-06-17.