![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.851577 |
Category: | SuSE Local Security Checks |
Title: | openSUSE: Security Advisory for xen (openSUSE-SU-2017:1826-1) |
Summary: | The remote host is missing an update for the 'xen'; package(s) announced via the referenced advisory. |
Description: | Summary: The remote host is missing an update for the 'xen' package(s) announced via the referenced advisory. Vulnerability Insight: This update for xen fixes several issues. These security issues were fixed: - CVE-2017-10912: Page transfer might have allowed PV guest to elevate privilege (XSA-217, bsc#1042882) - CVE-2017-10913 CVE-2017-10914: Races in the grant table unmap code allowed for information leaks and potentially privilege escalation (XSA-218, bsc#1042893) - CVE-2017-10915: Insufficient reference counts during shadow emulation allowed a malicious pair of guest to elevate their privileges to the privileges that XEN runs under (XSA-219, bsc#1042915) - CVE-2017-10917: Missing NULL pointer check in event channel poll allows guests to DoS the host (XSA-221, bsc#1042924) - CVE-2017-10918: Stale P2M mappings due to insufficient error checking allowed malicious guest to leak information or elevate privileges (XSA-222, bsc#1042931) - CVE-2017-10920, CVE-2017-10921, CVE-2017-10922: Grant table operations mishandled reference counts allowing malicious guests to escape (XSA-224, bsc#1042938) - CVE-2017-9330: USB OHCI Emulation in qemu allowed local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value (bsc#1042160) - CVE-2017-8309: Memory leak in the audio/audio.c allowed remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture (bsc#1037243) - PKRU and BND* leakage between vCPU-s might have leaked information to other guests (XSA-220, bsc#1042923) These non-security issues were fixed: - bsc#1027519: Included various upstream patches - bsc#1035642: Ensure that rpmbuild works This update was imported from the SUSE:SLE-12-SP2:Update update project. Affected Software/OS: xen on openSUSE Leap 42.2 Solution: Please install the updated package(s). CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-10912 BugTraq ID: 99158 http://www.securityfocus.com/bid/99158 Debian Security Information: DSA-3969 (Google Search) http://www.debian.org/security/2017/dsa-3969 https://security.gentoo.org/glsa/201708-03 https://security.gentoo.org/glsa/201710-17 http://www.securitytracker.com/id/1038721 Common Vulnerability Exposure (CVE) ID: CVE-2017-10913 BugTraq ID: 99411 http://www.securityfocus.com/bid/99411 http://www.securitytracker.com/id/1038722 Common Vulnerability Exposure (CVE) ID: CVE-2017-10914 Common Vulnerability Exposure (CVE) ID: CVE-2017-10915 BugTraq ID: 99174 http://www.securityfocus.com/bid/99174 Common Vulnerability Exposure (CVE) ID: CVE-2017-10917 BugTraq ID: 99157 http://www.securityfocus.com/bid/99157 http://www.securitytracker.com/id/1038731 Common Vulnerability Exposure (CVE) ID: CVE-2017-10918 BugTraq ID: 99161 http://www.securityfocus.com/bid/99161 http://www.securitytracker.com/id/1038732 Common Vulnerability Exposure (CVE) ID: CVE-2017-10920 http://www.securitytracker.com/id/1038734 Common Vulnerability Exposure (CVE) ID: CVE-2017-10921 Common Vulnerability Exposure (CVE) ID: CVE-2017-10922 Common Vulnerability Exposure (CVE) ID: CVE-2017-8309 BugTraq ID: 98302 http://www.securityfocus.com/bid/98302 https://security.gentoo.org/glsa/201706-03 https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg05587.html RedHat Security Advisories: RHSA-2017:2408 https://access.redhat.com/errata/RHSA-2017:2408 Common Vulnerability Exposure (CVE) ID: CVE-2017-9330 BugTraq ID: 98779 http://www.securityfocus.com/bid/98779 Debian Security Information: DSA-3920 (Google Search) http://www.debian.org/security/2017/dsa-3920 http://www.openwall.com/lists/oss-security/2017/06/01/3 |
Copyright | Copyright (C) 2017 Greenbone Networks GmbH |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |