PT-2013-3134 · Xen+1 · Xen+1
Andrew Cooper
·
Publicado
2013-07-01
·
Atualizado
2017-06-30
·
CVE-2013-1432
CVSS v2.0
7.4
Alta
| Vetor | AV:A/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.1.x through 4.2.x
Description
The issue is related to the improper maintenance of references on pages stored for deferred cleanup. This can be exploited by local PV guest kernels to cause a denial of service, resulting in a premature page free and hypervisor crash, or possibly gain privileges via unspecified vectors.
Recommendations
For Xen versions 4.1.x through 4.2.x, consider applying the necessary patches to fix the issue, specifically ensuring that the XSA-45 patch is properly applied and the deferred cleanup mechanism is corrected to prevent premature page freeing and potential privilege escalation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Xen