Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71820
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2531-1)
Summary:The remote host is missing an update for the Debian 'xen' package(s) announced via the DSA-2531-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'xen' package(s) announced via the DSA-2531-1 advisory.

Vulnerability Insight:
Several denial-of-service vulnerabilities have been discovered in Xen, the popular virtualization software. The Common Vulnerabilities and Exposures project identifies the following issues:

CVE-2012-3432

Guest mode unprivileged code, which has been granted the privilege to access MMIO regions, may leverage that access to crash the whole guest. Since this can be used to crash a client from within, this vulnerability is considered to have low impact.

CVE-2012-3433

A guest kernel can cause the host to become unresponsive for a period of time, potentially leading to a DoS. Since an attacker with full control in the guest can impact the host, this vulnerability is considered to have high impact.

For the stable distribution (squeeze), this problem has been fixed in version 4.0.1-5.3.

For the unstable distribution (sid), this problem has been fixed in version 4.1.3-1.

We recommend that you upgrade your xen packages.

Affected Software/OS:
'xen' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
4.9

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-3432
54691
http://www.securityfocus.com/bid/54691
55082
http://secunia.com/advisories/55082
DSA-2531
http://www.debian.org/security/2012/dsa-2531
GLSA-201309-24
http://security.gentoo.org/glsa/glsa-201309-24.xml
SUSE-SU-2012:1043
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.html
SUSE-SU-2012:1044
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.html
[Xen-devel] 20120727 Xen Security Advisory 10 (CVE-2012-3432) - HVM user mode MMIO emul DoS
http://lists.xen.org/archives/html/xen-devel/2012-07/msg01649.html
openSUSE-SU-2012:1172
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
openSUSE-SU-2012:1174
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-3433
54942
http://www.securityfocus.com/bid/54942
[Xen-devel] 20120809 Xen Security Advisory 11 (CVE-2012-3433) - HVM destroy p2m host DoS
http://lists.xen.org/archives/html/xen-devel/2012-08/msg00855.html
[oss-security] 20120809 Xen Security Advisory 11 (CVE-2012-3433) - HVM destroy p2m host DoS
http://www.openwall.com/lists/oss-security/2012/08/09/3
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.