CVE Vulnerabilities

CVE-2016-4962

Published: Jun 07, 2016 | Modified: Nov 28, 2016
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.

Affected Software

Name Vendor Start Version End Version
Vm_server Oracle 3.3 (including) 3.3 (including)
Vm_server Oracle 3.4 (including) 3.4 (including)
Xen Ubuntu devel *
Xen Ubuntu precise *
Xen Ubuntu trusty *
Xen Ubuntu wily *
Xen Ubuntu xenial *

References