Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
BID:100818
CVE-2017-14316 |Info
Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 100818 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-14316 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Matthew Daley. |
| Vulnerable: |
Xen Xen 4.9 Xen Xen 4.8 Xen Xen 4.7 Xen Xen 4.6 Xen Xen 4.0.4 Xen Xen 4.0.1 Xen Xen 4.9 Xen Xen 4.6.3 Xen Xen 4.5.3 Xen Xen 4.5.0 Xen Xen 4.4.1 Xen Xen 4.4.0 - Xen Xen 4.4.0 Xen Xen 4.4 Xen Xen 4.3.1 Xen Xen 4.3.0-1 Xen Xen 4.3.0 Xen Xen 4.3 Xen Xen 4.2.3 Xen Xen 4.2.2 Xen Xen 4.2.1 Xen Xen 4.2.0 Xen Xen 4.2 Xen Xen 4.1.6.1 Xen Xen 4.1.5 Xen Xen 4.1.4 Xen Xen 4.1.3 Xen Xen 4.1.2 Xen Xen 4.1.1 Xen Xen 4.1.0 Xen Xen 4.1 Xen Xen 4.0.3 Xen Xen 4.0.2 Xen Xen 4.0.0 Xen Xen 4.0 Xen Xen 3.4.4 Xen Xen 3.4.3 Xen Xen 3.4.2 Xen Xen 3.4.1 Xen Xen 3.4.0 Xen Xen 3.3.2 Xen Xen 3.3.1 Xen Xen 3.3.0 Xen Xen 3.3 Xen Xen 3.2.3 Xen Xen 3.2.2 Xen Xen 3.2.1 Xen Xen 3.2.0 Xen Xen 3.2 Xen Xen 3.1.4 Xen Xen 3.1.3 Xen Xen 3.1 Xen Xen 3.0.4 Xen Xen 3.0.3 Xen Xen 3.0.2 Xen Xen 2.0 Redhat Enterprise Linux 5 |
| Not Vulnerable: | |
Discussion
Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
Xen is prone to an arbitrary code execution vulnerability.
Successful exploits allow attackers to execute arbitrary code in the context of the host operating system. Failed exploit attempts will result in a denial of service condition.
Xen is prone to an arbitrary code execution vulnerability.
Successful exploits allow attackers to execute arbitrary code in the context of the host operating system. Failed exploit attempts will result in a denial of service condition.
Exploit / POC
Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen CVE-2017-14316 Arbitrary Code Execution Vulnerability
References:
References:
- Xen HomePage (Xen)
- Bug 1486707 - (CVE-2017-14316, xsa231) CVE-2017-14316 xsa231 xen: Missing NUMA n (Redhat)
- CVE-2017-14316 (Redhat)
- XSA-231 (Xen)