Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10472

Опубликовано: 27 апр. 2018
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6package
xennot-affectedwheezypackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-258.html

EPSS

Процентиль: 25%
0.00088
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 6.5
redhat
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
nvd
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
github
больше 3 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

suse-cvrf
больше 7 лет назад

Security update for xen

EPSS

Процентиль: 25%
0.00088
Низкий