Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.852977
Categoría:SuSE Local Security Checks
Título:openSUSE: Security Advisory for xen (openSUSE-SU-2020:0011-1)
Resumen:The remote host is missing an update for the 'xen'; package(s) announced via the openSUSE-SU-2020:0011-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'xen'
package(s) announced via the openSUSE-SU-2020:0011-1 advisory.

Vulnerability Insight:
This update for xen fixes the following issues:

- CVE-2019-19581: Fixed a potential out of bounds on 32-bit Arm
(bsc#1158003 XSA-307).

- CVE-2019-19582: Fixed a potential infinite loop when x86 accesses to
bitmaps with a compile time known size of 64 (bsc#1158003 XSA-307).

- CVE-2019-19583: Fixed improper checks which could have allowed HVM/PVH
guest userspace code to crash the guest, leading to a guest denial of
service (bsc#1158004 XSA-308).

- CVE-2019-19578: Fixed an issue where a malicious or buggy PV guest could
have caused hypervisor crash resulting in denial of service affecting
the entire host (bsc#1158005 XSA-309).

- CVE-2019-19580: Fixed a privilege escalation where a malicious PV guest
administrator could have been able to escalate their privilege to that
of the host (bsc#1158006 XSA-310).

- CVE-2019-19577: Fixed an issue where a malicious guest administrator
could have caused Xen to access data structures while they are being
modified leading to a crash (bsc#1158007 XSA-311).

- CVE-2019-19579: Fixed a privilege escaltion where an untrusted domain
with access to a physical device can DMA into host memory (bsc#1157888
XSA-306).

- Fixed an issue where PCI passthrough failed on AMD machine xen host
(bsc#1157047).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended
installation methods
like YaST online_update or 'zypper patch'.

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-11=1

Affected Software/OS:
'xen' package(s) on openSUSE Leap 15.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2019-19581
Common Vulnerability Exposure (CVE) ID: CVE-2019-19582
Common Vulnerability Exposure (CVE) ID: CVE-2019-19583
Common Vulnerability Exposure (CVE) ID: CVE-2019-19578
Common Vulnerability Exposure (CVE) ID: CVE-2019-19580
Common Vulnerability Exposure (CVE) ID: CVE-2019-19577
Common Vulnerability Exposure (CVE) ID: CVE-2019-19579
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.