MEDIUM
xen: oxenstored incorrect handling of certain Xenbus ring states
Published Mar 7, 2013
4.3
MEDIUMCVSS 2.0
EPSS 0.59%
Description
oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive control-plane data by leveraging guest administrative access.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
xen
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of the xen package as shipped with Red Hat Enterprise Linux 5.
Weaknesses (1)
References (10)
- http://openwall.com/lists/oss-security/2013/02/05/10 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/55082 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201309-24.xml vendor-advisoryx_refsource_GENTOO
- http://xenbits.xen.org/gitweb/?p=xen.git%3Ba=commit%3Bh=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5 x_refsource_CONFIRM
- http://xenbits.xen.org/gitweb/?p=xen.git%3Ba=commit%3Bh=61401264eb00fae4ee4efc8e9a5067449283207b x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2013-0215 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=906323 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0249 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-0215
- https://www.cve.org/CVERecord?id=CVE-2013-0215
| Link | Providers | Tags |
|---|---|---|
| http://openwall.com/lists/oss-security/2013/02/05/10 | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/55082 | third-party-advisoryx_refsource_SECUNIA | |
| http://security.gentoo.org/glsa/glsa-201309-24.xml | vendor-advisoryx_refsource_GENTOO | |
| http://xenbits.xen.org/gitweb/?p=xen.git%3Ba=commit%3Bh=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5 | x_refsource_CONFIRM | |
| http://xenbits.xen.org/gitweb/?p=xen.git%3Ba=commit%3Bh=61401264eb00fae4ee4efc8e9a5067449283207b | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2013-0215 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=906323 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0249 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-0215 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-0215 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 7, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2013-0215
CISA Vulnrichment
No data
GitHub
No data