[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3729-1 xen -- xen

ID: oval:org.secpod.oval:def:602691Date: (C)2016-12-09   (M)2023-12-07
Class: PATCHFamily: unix




Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-7777 Jan Beulich from SUSE discovered that Xen does not properly honor CR0.TS and CR0.EM for x86 HVM guests, potentially allowing guest users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it. CVE-2016-9379, CVE-2016-9380 Daniel Richman and Gabor Szarka of the Cambridge University Student-Run Computing Facility discovered that pygrub, the boot loader emulator, fails to quote its results when reporting them to its caller. A malicious guest administrator can take advantage of this flaw to cause an information leak or denial of service. CVE-2016-9382 Jan Beulich of SUSE discovered that Xen does not properly handle x86 task switches to VM86 mode. A unprivileged guest process can take advantage of this flaw to crash the guest or, escalate its privileges to that of the guest operating system. CVE-2016-9383 George Dunlap of Citrix discovered that the Xen x86 64-bit bit test instruction emulation is broken. A malicious guest can take advantage of this flaw to modify arbitrary memory, allowing for arbitrary code execution, denial of service , or information leaks. CVE-2016-9385 Andrew Cooper of Citrix discovered that Xen"s x86 segment base write emulation lacks canonical address checks. A malicious guest administrator can take advantage of this flaw to crash the host, leading to a denial of service. CVE-2016-9386 Andrew Cooper of Citrix discovered that x86 null segments are not always treated as unusable. An unprivileged guest user program may be able to elevate its privilege to that of the guest operating system.

Platform:
Debian 8.x
Product:
xen-utils-4.4
Reference:
DSA-3729-1
CVE-2016-7777
CVE-2016-9379
CVE-2016-9380
CVE-2016-9382
CVE-2016-9383
CVE-2016-9385
CVE-2016-9386
CVE    7
CVE-2016-7777
CVE-2016-9386
CVE-2016-9385
CVE-2016-9383
...
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:xen:xen-utils-4.4

© SecPod Technologies