Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105145
Category:Citrix Xenserver Local Security Checks
Title:Citrix XenServer Multiple Security Updates (CTX140984)
Summary:A number of security vulnerabilities have been identified in Citrix XenServer.; These vulnerabilities affect all currently supported versions of Citrix XenServer up to and including Citrix; XenServer 6.2 Service Pack 1.
Description:Summary:
A number of security vulnerabilities have been identified in Citrix XenServer.
These vulnerabilities affect all currently supported versions of Citrix XenServer up to and including Citrix
XenServer 6.2 Service Pack 1.

Vulnerability Insight:
The following vulnerabilities have been addressed:

- CVE-2014-4021: Citrix XenServer potential guest information leak through hypervisor page reuse

- CVE-2014-4947: Buffer overflow in Citrix XenServer HVM graphics console support

- CVE-2014-4948: Citrix XenServer guest denial of service and information leak through guest VHD modification

Affected Software/OS:
Citrix XenServer 6.2 Service Pack 1

Citrix XenServer 6.1

Citrix XenServer 6.0.2

Citrix XenServer 6.0.0

Solution:
Apply the hotfix referenced in the advisory.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-4021
BugTraq ID: 68070
http://www.securityfocus.com/bid/68070
Debian Security Information: DSA-3006 (Google Search)
http://www.debian.org/security/2014/dsa-3006
http://lists.fedoraproject.org/pipermail/package-announce/2014-July/135071.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-July/135068.html
http://security.gentoo.org/glsa/glsa-201407-03.xml
http://www.securitytracker.com/id/1030442
http://secunia.com/advisories/59208
http://secunia.com/advisories/60027
http://secunia.com/advisories/60130
http://secunia.com/advisories/60471
SuSE Security Announcement: openSUSE-SU-2014:1279 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.html
SuSE Security Announcement: openSUSE-SU-2014:1281 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4947
BugTraq ID: 68659
http://www.securityfocus.com/bid/68659
http://www.securitytracker.com/id/1030604
XForce ISS Database: citrix-xenserver-cve20144947-bo(94631)
https://exchange.xforce.ibmcloud.com/vulnerabilities/94631
Common Vulnerability Exposure (CVE) ID: CVE-2014-4948
BugTraq ID: 68660
http://www.securityfocus.com/bid/68660
XForce ISS Database: xenserver-cve20144948-dos(94632)
https://exchange.xforce.ibmcloud.com/vulnerabilities/94632
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.