Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10472

Опубликовано: 27 апр. 2018
Источник: debian

Описание

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6package
xennot-affectedwheezypackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-258.html

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 6.5
redhat
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
nvd
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
github
больше 4 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

suse-cvrf
больше 8 лет назад

Security update for xen