PT-2015-1367 · Xen+2 · Xen+2

Jan Beulich

·

Publicado

2015-06-03

·

Atualizado

2024-06-15

·

CVE-2015-4104

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.5.x
Description The issue is related to insufficient access restrictions to certain functions in the Xen hypervisor. This can be exploited by an attacker, potentially allowing them to cause a denial of service using a guest operating system. The exploitation can lead to unexpected interrupts and host crashes.
Recommendations For Xen versions 3.3.x through 4.5.x, consider restricting access to the PCI MSI mask bits to prevent local x86 HVM guest users from causing a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10459
CVE-2015-4104
DSA-3284-1
DSA-3286-1
MGASA-2015-0310
MGASA-2016-0098
OPENSUSE-SU-2015_1092-1
OPENSUSE-SU-2015_1094-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:1042-1
SUSE-SU-2015:1045-1
SUSE-SU-2015:1156-1
SUSE-SU-2015:1157-1
USN-2630-1

Produtos afetados

Suse
Ubuntu
Xen