CVE Vulnerabilities

CVE-2013-2211

Published: Aug 28, 2013 | Modified: Dec 12, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.4 HIGH
AV:A/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.2.0 (including) 4.2.0 (including)
Xen Xen 4.2.1 (including) 4.2.1 (including)
Xen Xen 4.2.2 (including) 4.2.2 (including)

References