Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17347

Опубликовано: 08 окт. 2019
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.11.1+92-g6c33308a8d-1package
xenfixed4.8.5.final+shim4.10.4-1+deb9u12stretchpackage
xenend-of-lifejessiepackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-293.html

EPSS

Процентиль: 21%
0.00069
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
redhat
больше 6 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
nvd
больше 6 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость гипервизора Xen, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных

EPSS

Процентиль: 21%
0.00069
Низкий