Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10472

Опубликовано: 25 апр. 2018
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1566253xen: Information leak via crafted user-supplied CDROM

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
nvd
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

CVSS3: 5.6
debian
почти 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest O ...

CVSS3: 5.6
github
больше 3 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

suse-cvrf
больше 7 лет назад

Security update for xen

6.5 Medium

CVSS3