PT-2013-3532 · Xen+1 · Xen+1

Published

2013-07-01

·

Updated

2014-12-12

·

CVE-2013-2078

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 4.0.2 through 4.0.4 Xen versions 4.1.x Xen versions 4.2.x
Description The issue allows local PV guest users to cause a denial of service, resulting in a hypervisor crash, by using certain bit combinations with the XSETBV instruction.
Recommendations For Xen versions 4.0.2 through 4.0.4, update to a version that includes the fix for this issue. For Xen versions 4.1.x, update to a version that includes the fix for this issue. For Xen versions 4.2.x, update to a version that includes the fix for this issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2078
DSA-3006-1
MGASA-2013-0197

Affected Products

Suse
Xen