Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Update for xen RHSA-2015:1002-01
Summary:The remote host is missing an update for the 'xen'; package(s) announced via the referenced advisory.
The remote host is missing an update for the 'xen'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The xen packages contain administration tools and the xend service for
managing the kernel-xen kernel for virtualization on Red Hat Enterprise

An out-of-bounds memory access flaw was found in the way QEMU's virtual
Floppy Disk Controller (FDC) handled FIFO buffer access while processing
certain FDC commands. A privileged guest user could use this flaw to crash
the guest or, potentially, execute arbitrary code on the host with the
privileges of the host's QEMU process corresponding to the guest.

Red Hat would like to thank Jason Geffner of CrowdStrike for reporting
this issue.

All xen users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, all running fully-virtualized guests must be restarted
for this update to take effect.

Affected Software/OS:
xen on Red Hat Enterprise Linux (v. 5 server)

Please Install the Updated Packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-3456
BugTraq ID: 74640
Debian Security Information: DSA-3259 (Google Search)
Debian Security Information: DSA-3262 (Google Search)
Debian Security Information: DSA-3274 (Google Search)
HPdes Security Advisory: HPSBMU03336
HPdes Security Advisory: HPSBMU03349
HPdes Security Advisory: SSRT102076
RedHat Security Advisories: RHSA-2015:0998
RedHat Security Advisories: RHSA-2015:0999
RedHat Security Advisories: RHSA-2015:1000
RedHat Security Advisories: RHSA-2015:1001
RedHat Security Advisories: RHSA-2015:1002
RedHat Security Advisories: RHSA-2015:1003
RedHat Security Advisories: RHSA-2015:1004
RedHat Security Advisories: RHSA-2015:1011
SuSE Security Announcement: SUSE-SU-2015:0889 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:0896 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:0923 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:0927 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:0929 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:0893 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:0894 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:0983 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:1400 (Google Search)
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.