CVE-2012-3515

high
Published 2012-11-23 · Modified 2026-04-29
CVSS v3
CVSS v2
7.2
VIR risk
7.2

Description

Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3515

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/09/05/10

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://wiki.xen.org/wiki/Security_Announcements#XSA-17_Qemu_VT100_emulation_vulnerability

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.xen.org/archives/html/xen-announce/2012-09/msg00003.html

OS impact

OSVersionStatusFixed in
suse suse11.4affected
suse suse12.1affected
suse suse12.2affected
suse suse10affected
suse suse11affected
redhat rhel6.0not-affected
redhat rhel5.0affected
redhat rhel6.3affected
debian debian6.0affected
debian debian7.0affected
ubuntu ubuntu10.04affected
ubuntu ubuntu11.04affected
ubuntu ubuntu11.10affected
ubuntu ubuntu12.04affected
debian debianbookwormfixed1.1.2+dfsg-1
debian debianbullseyefixed1.1.2+dfsg-1
debian debianforkyfixed1.1.2+dfsg-1
debian debiansidfixed1.1.2+dfsg-1
debian debiantrixiefixed1.1.2+dfsg-1

Application impact

VendorProductVersionsFixed
qemuqemu{"endExcluding":"1.2.0"}1.2.0
redhat redhatvirtualization3.0
redhat redhatvirtualization5.0
redhat redhatvirtualization6.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.