[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3554-1 xen -- xen

ID: oval:org.secpod.oval:def:602472Date: (C)2016-04-28   (M)2023-12-07
Class: PATCHFamily: unix




Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-3158, CVE-2016-3159 Jan Beulich from SUSE discovered that Xen does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors. A malicious domain can take advantage of this flaw to obtain address space usage and timing information, about another domain, at a fairly low rate. CVE-2016-3960 Ling Liu and Yihan Lian of the Cloud Security Team, Qihoo 360 discovered an integer overflow in the x86 shadow pagetable code. A HVM guest using shadow pagetables can cause the host to crash. A PV guest using shadow pagetables with PV superpages enabled can crash the host, or corrupt hypervisor memory, potentially leading to privilege escalation.

Platform:
Debian 8.x
Product:
xen-utils-4.4
Reference:
DSA-3554-1
CVE-2016-3158
CVE-2016-3159
CVE-2016-3960
CVE    3
CVE-2016-3158
CVE-2016-3159
CVE-2016-3960
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:xen:xen-utils-4.4

© SecPod Technologies