Back

LOW

xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)

Published Mar 18, 2015

Description

Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of xen as shipped with Red Hat Enterprise Linux 5 as they did not include affected libxc library.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 18, 2015
Updated Aug 6, 2024
Reserved Feb 28, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 12, 2015