Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-2963

Опубликовано: 20 дек. 2016
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2016-2963: xen security update (IMPORTANT)

[3.0.3-148.el5_11]

  • xen-qemu-ioport-array-overflow.patch [bz#1401521]
  • Resolves: bz#1401521 (CVE-2016-9637 xsa199 xen: qemu ioport array overflow (XSA-199) [rhel-5.11.z])

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

xen

3.0.3-148.el5_11

xen-devel

3.0.3-148.el5_11

xen-libs

3.0.3-148.el5_11

Oracle Linux x86_64

xen

3.0.3-148.el5_11

xen-devel

3.0.3-148.el5_11

xen-libs

3.0.3-148.el5_11

Oracle Linux i386

xen

3.0.3-148.el5_11

xen-devel

3.0.3-148.el5_11

xen-libs

3.0.3-148.el5_11

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

CVSS3: 7.6
redhat
почти 9 лет назад

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

CVSS3: 7.5
nvd
больше 8 лет назад

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

CVSS3: 7.5
debian
больше 8 лет назад

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu i ...

CVSS3: 7.5
github
больше 3 лет назад

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.