PT-2018-9892 · Xen+1 · Xen+1

Anthony Perard

·

Published

2018-04-27

·

Updated

2024-06-15

·

CVE-2018-10472

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Xen versions prior to 4.11
Description: An issue allows x86 HVM guest OS users to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Recommendations: For versions prior to 4.11, update to version 4.11 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10472
DLA-1559-1
DSA-4201-1
OPENSUSE-SU-2018_1274-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2018:1177-1
SUSE-SU-2018:1181-1
SUSE-SU-2018:1184-1
SUSE-SU-2018:1202-1
SUSE-SU-2018:1203-1
SUSE-SU-2018:1216-1
SUSE-SU-2018:3230-1

Affected Products

Suse
Xen