Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.105895
Kategorie:Citrix Xenserver Local Security Checks
Titel:Citrix XenServer Multiple Security Updates (CTX216071)
Zusammenfassung:A number of security vulnerabilities have been identified in; Citrix XenServer that may allow malicious privileged code running within a guest VM to compromise the host.
Beschreibung:Summary:
A number of security vulnerabilities have been identified in
Citrix XenServer that may allow malicious privileged code running within a guest VM to compromise the host.

Vulnerability Insight:
The following vulnerabilities have been addressed:

- CVE-2016-7092 (High): x86: Disallow L3 recursive pagetable for 32-bit guests

- CVE-2016-7093 (High): x86: Mishandling of instruction pointer truncation during emulation

- CVE-2016-7094 (Medium): x86 HVM: Overflow of sh_ctxt->seg_reg[]

- CVE-2016-7154 (High): use after free in FIFO event channel code

Affected Software/OS:
These vulnerabilities affect all currently supported versions of Citrix XenServer up to and including Citrix XenServer 7.0.

Solution:
Apply the hotfix referenced in the advisory.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-7092
BugTraq ID: 92862
http://www.securityfocus.com/bid/92862
Debian Security Information: DSA-3663 (Google Search)
http://www.debian.org/security/2016/dsa-3663
https://security.gentoo.org/glsa/201611-09
http://www.securitytracker.com/id/1036751
Common Vulnerability Exposure (CVE) ID: CVE-2016-7093
BugTraq ID: 92865
http://www.securityfocus.com/bid/92865
http://www.securitytracker.com/id/1036752
Common Vulnerability Exposure (CVE) ID: CVE-2016-7094
BugTraq ID: 92864
http://www.securityfocus.com/bid/92864
http://www.securitytracker.com/id/1036753
Common Vulnerability Exposure (CVE) ID: CVE-2016-7154
BugTraq ID: 92863
http://www.securityfocus.com/bid/92863
http://www.c7zero.info/stuff/csw2017_ExploringYourSystemDeeper_updated.pdf
http://www.securitytracker.com/id/1036754
CopyrightCopyright (C) 2016 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.