PT-2013-2137 · Xen+1 · Xen+1
Publicado
2013-01-12
·
Atualizado
2017-08-29
·
CVE-2013-0154
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Xen version 4.2
Description
The issue is related to the get page type function in Xen, which can cause a denial of service when debugging is enabled. This can lead to an assertion failure and hypervisor crash. The issue is exploited via unspecified vectors related to a hypercall.
Recommendations
For Xen version 4.2, consider disabling the debugging feature to prevent the denial of service. As a temporary workaround, restrict access to the get page type function until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse
Xen