Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8904

Опубликовано: 11 мая 2017
Источник: debian
EPSS Низкий

Описание

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.8.1-1+deb9u1package

Примечания

  • https://xenbits.xen.org/xsa/advisory-214.html

EPSS

Процентиль: 25%
0.00087
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

CVSS3: 8.5
redhat
почти 9 лет назад

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

CVSS3: 8.8
nvd
больше 8 лет назад

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

CVSS3: 8.8
github
больше 3 лет назад

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

EPSS

Процентиль: 25%
0.00087
Низкий