CVE Vulnerabilities

CVE-2013-4554

Published: Dec 24, 2013 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.2 MEDIUM
AV:A/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:L/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.

Affected Software

Name Vendor Start Version End Version
Xen Xen 3.0.3 (including) 3.0.3 (including)
Xen Xen 3.0.4 (including) 3.0.4 (including)
Xen Xen 3.1.3 (including) 3.1.3 (including)
Xen Xen 3.1.4 (including) 3.1.4 (including)
Xen Xen 3.2.0 (including) 3.2.0 (including)
Xen Xen 3.2.1 (including) 3.2.1 (including)
Xen Xen 3.2.2 (including) 3.2.2 (including)
Xen Xen 3.2.3 (including) 3.2.3 (including)
Xen Xen 3.3.0 (including) 3.3.0 (including)
Xen Xen 3.3.1 (including) 3.3.1 (including)
Xen Xen 3.3.2 (including) 3.3.2 (including)
Xen Xen 3.4.0 (including) 3.4.0 (including)
Xen Xen 3.4.1 (including) 3.4.1 (including)
Xen Xen 3.4.2 (including) 3.4.2 (including)
Xen Xen 3.4.3 (including) 3.4.3 (including)
Xen Xen 3.4.4 (including) 3.4.4 (including)
Xen Xen 4.0.0 (including) 4.0.0 (including)
Xen Xen 4.0.1 (including) 4.0.1 (including)
Xen Xen 4.0.2 (including) 4.0.2 (including)
Xen Xen 4.0.3 (including) 4.0.3 (including)
Xen Xen 4.0.4 (including) 4.0.4 (including)
Xen Xen 4.1.0 (including) 4.1.0 (including)
Xen Xen 4.1.1 (including) 4.1.1 (including)
Xen Xen 4.1.2 (including) 4.1.2 (including)
Xen Xen 4.1.3 (including) 4.1.3 (including)
Xen Xen 4.1.4 (including) 4.1.4 (including)
Xen Xen 4.1.5 (including) 4.1.5 (including)
Xen Xen 4.1.6.1 (including) 4.1.6.1 (including)
Red Hat Enterprise Linux 5 RedHat kernel-0:2.6.18-371.6.1.el5 *
Xen Ubuntu devel *
Xen Ubuntu precise *
Xen Ubuntu quantal *
Xen Ubuntu raring *
Xen Ubuntu saucy *
Xen-3.3 Ubuntu lucid *
Xen-3.3 Ubuntu upstream *

References