Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.72173
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2544-1 (xen)
Zusammenfassung:The remote host is missing an update to xen;announced via advisory DSA 2544-1.
Beschreibung:Summary:
The remote host is missing an update to xen
announced via advisory DSA 2544-1.

Vulnerability Insight:
Multiple denial of service vulnerabilities have been discovered in xen,
an hypervisor. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2012-3494:

It was discovered that set_debugreg allows writes to reserved bits
of the DR7 debug control register on amd64 (x86-64) paravirtualised
guests, allowing a guest to crash the host.

CVE-2012-3496:

Matthew Daley discovered that XENMEM_populate_physmap, when called
with the MEMF_populate_on_demand flag set, a BUG (detection routine)
can be triggered if a translating paging mode is not being used,
allowing a guest to crash the host.

For the stable distribution (squeeze), these problems have been fixed in
version 4.0.1-5.4.

For the testing distribution (wheezy), these problems will be fixed
soon.

For the unstable distribution (sid), these problems have been fixed in
version 4.1.3-2.

Solution:
We recommend that you upgrade your xen packages.

CVSS Score:
4.7

CVSS Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-3494
BugTraq ID: 55400
http://www.securityfocus.com/bid/55400
Debian Security Information: DSA-2544 (Google Search)
http://www.debian.org/security/2012/dsa-2544
http://security.gentoo.org/glsa/glsa-201309-24.xml
https://security.gentoo.org/glsa/201604-03
http://wiki.xen.org/wiki/Security_Announcements#XSA-12_hypercall_set_debugreg_vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=851139
http://lists.xen.org/archives/html/xen-announce/2012-09/msg00000.html
http://www.openwall.com/lists/oss-security/2012/09/05/5
http://osvdb.org/85197
http://www.securitytracker.com/id?1027479
http://secunia.com/advisories/50472
http://secunia.com/advisories/50530
http://secunia.com/advisories/51413
http://secunia.com/advisories/55082
SuSE Security Announcement: SUSE-SU-2012:1129 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.html
SuSE Security Announcement: SUSE-SU-2012:1132 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.html
SuSE Security Announcement: SUSE-SU-2012:1133 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
SuSE Security Announcement: SUSE-SU-2012:1135 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.html
SuSE Security Announcement: SUSE-SU-2012:1162 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.html
SuSE Security Announcement: openSUSE-SU-2012:1172 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
SuSE Security Announcement: openSUSE-SU-2012:1174 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
SuSE Security Announcement: openSUSE-SU-2012:1572 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
SuSE Security Announcement: openSUSE-SU-2012:1573 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
XForce ISS Database: xen-setdebugreg-dos(78265)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78265
Common Vulnerability Exposure (CVE) ID: CVE-2012-3496
BugTraq ID: 55412
http://www.securityfocus.com/bid/55412
https://bugzilla.redhat.com/show_bug.cgi?id=854590
http://lists.xen.org/archives/html/xen-announce/2012-09/msg00002.html
http://www.openwall.com/lists/oss-security/2012/09/05/7
http://www.osvdb.org/85200
http://securitytracker.com/id?1027481
XForce ISS Database: xen-xenmempopulatephysmap-dos(78267)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78267
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.