PT-2015-1571 · Xen+2 · Xen+2

Jan Beulich

·

Publicado

2015-06-03

·

Atualizado

2024-06-15

·

CVE-2015-4103

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.5.x
Description The issue is related to inadequate access control for certain functions in the Xen hypervisor. Exploitation of this issue can allow a local attacker to cause a denial of service in the host operating system. Specifically, the problem lies in the lack of proper restriction on write access to the host MSI message data field, which can be exploited by local x86 HVM guest administrators to cause confusion in host interrupt handling. This can be achieved through vectors related to qemu and accessing spanning multiple fields.
Recommendations For Xen versions 3.3.x through 4.5.x, consider restricting access to the qemu module to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability of local x86 HVM guest administrators to access and modify the host MSI message data field.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10884
CVE-2015-4103
DSA-3284-1
DSA-3286-1
MGASA-2015-0310
MGASA-2016-0098
OPENSUSE-SU-2015_1092-1
OPENSUSE-SU-2015_1094-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:1042-1
SUSE-SU-2015:1045-1
SUSE-SU-2015:1156-1
SUSE-SU-2015:1157-1
USN-2630-1

Produtos afetados

Suse
Ubuntu
Xen