PT-2018-2671 · Amd+1 · Xen+1

Paul Durrant

·

Publicado

2018-12-07

·

Atualizado

2019-10-08

·

CVE-2018-19962

CVSS v3.1

7.8

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.12
Description An issue in Xen on AMD x86 platforms allows guest OS users to potentially gain host OS privileges due to the unsafe combination of small IOMMU mappings into larger ones. This could enable an attacker to elevate their privileges.
Recommendations For Xen versions prior to 4.12, update to a version that includes the fix for this issue to prevent potential privilege escalation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01306
CVE-2018-19962
DLA-1949-1
DSA-4369-1
OPENSUSE-SU-2018_4111-1
OPENSUSE-SU-2018_4304-1
OPENSUSE-SU-2019_1226-1
SUSE-SU-2018:4070-1
SUSE-SU-2018:4300-1
SUSE-SU-2019:0003-1
SUSE-SU-2019:0020-1
SUSE-SU-2019:0825-1
SUSE-SU-2019:0827-1
SUSE-SU-2019:13921-1
SUSE-SU-2019:14011-1

Produtos afetados

Suse
Xen