Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.140421
Kategorie:Citrix Xenserver Local Security Checks
Titel:Citrix XenServer Multiple Security Updates (CTX228867)
Zusammenfassung:A number of security vulnerabilities have been identified in Citrix; XenServer that may allow a malicious administrator of a guest VM to compromise the host.
Beschreibung:Summary:
A number of security vulnerabilities have been identified in Citrix
XenServer that may allow a malicious administrator of a guest VM to compromise the host.

Vulnerability Insight:
The following vulnerabilities have been addressed:

- CVE-2017-15595: Unlimited recursion in linear pagetable de-typing

- CVE-2017-15588: Stale TLB entry due to page type release race

- CVE-2017-15593: page type reference leak on x86

- CVE-2017-15592: x86: Incorrect handling of self-linear shadow mappings with translated guests

- CVE-2017-15594: x86: Incorrect handling of IST settings during CPU hotplug

- CVE-2017-15590: multiple MSI mapping issues on x86

- CVE-2017-15589: hypervisor stack leak in x86 I/O intercept code

For customers that do not have PV-based guests, are not using PCI passthrough and are using hardware with HAP
support, the risk is reduced to a disclosure of a small part of the hypervisor stack.

Affected Software/OS:
XenServer versions 7.2, 7.1, 7.0, 6.5, 6.2.0, 6.0.2.

Solution:
Apply the hotfix referenced in the advisory.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-15595
Debian Security Information: DSA-4050 (Google Search)
https://www.debian.org/security/2017/dsa-4050
https://www.exploit-db.com/exploits/43014/
https://security.gentoo.org/glsa/201801-14
https://lists.debian.org/debian-lts-announce/2017/11/msg00027.html
https://lists.debian.org/debian-lts-announce/2018/10/msg00021.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-15588
BugTraq ID: 101490
http://www.securityfocus.com/bid/101490
https://lists.debian.org/debian-lts-announce/2018/10/msg00009.html
http://www.securitytracker.com/id/1039568
Common Vulnerability Exposure (CVE) ID: CVE-2017-15593
Common Vulnerability Exposure (CVE) ID: CVE-2017-15592
BugTraq ID: 101513
http://www.securityfocus.com/bid/101513
BugTraq ID: 102129
http://www.securityfocus.com/bid/102129
Common Vulnerability Exposure (CVE) ID: CVE-2017-15594
Common Vulnerability Exposure (CVE) ID: CVE-2017-15590
BugTraq ID: 101500
http://www.securityfocus.com/bid/101500
Common Vulnerability Exposure (CVE) ID: CVE-2017-15589
BugTraq ID: 101496
http://www.securityfocus.com/bid/101496
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.