Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.140371
Kategorie:Citrix Xenserver Local Security Checks
Titel:Citrix XenServer Multiple Security Updates (CTX227185)
Zusammenfassung:A number of security vulnerabilities have been identified in Citrix; XenServer that may allow a malicious administrator of a guest VM to compromise the host.
Beschreibung:Summary:
A number of security vulnerabilities have been identified in Citrix
XenServer that may allow a malicious administrator of a guest VM to compromise the host.

Vulnerability Insight:
The following vulnerabilities have been addressed:

- CVE-2017-14316: (High) Missing NUMA node parameter verification.

- CVE-2017-14318: (Medium) Missing check for grant table.

- CVE-2017-14319: (High) insufficient grant unmapping checks for x86 PV guests.

Affected Software/OS:
XenServer versions 7.2, 7.1, 7.0, 6.5, 6.2.0, 6.0.2.

Solution:
Apply the hotfix referenced in the advisory.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-14316
BugTraq ID: 100818
http://www.securityfocus.com/bid/100818
Debian Security Information: DSA-4050 (Google Search)
https://www.debian.org/security/2017/dsa-4050
https://lists.debian.org/debian-lts-announce/2018/10/msg00009.html
http://www.securitytracker.com/id/1039348
Common Vulnerability Exposure (CVE) ID: CVE-2017-14318
BugTraq ID: 100817
http://www.securityfocus.com/bid/100817
http://www.securitytracker.com/id/1039349
Common Vulnerability Exposure (CVE) ID: CVE-2017-14319
BugTraq ID: 100819
http://www.securityfocus.com/bid/100819
http://www.securitytracker.com/id/1039351
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.