Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
BID:60701
Info
Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
| Bugtraq ID: | 60701 |
| Class: | Design Error |
| CVE: |
CVE-2013-2195 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2013 12:00AM |
| Updated: | Apr 16 2015 06:03PM |
| Credit: | Xen.org security team |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP3 LTSS Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Citrix XenServer 6.0 Citrix XenServer 5.6 SP2 Citrix XenServer 5.6 Feature Pack 1 Citrix XenServer 5.6 Citrix XenServer 5.5 Citrix XenServer 5.0 Update 3 |
| Not Vulnerable: | |
Discussion
Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
Xen is prone to a privilege-escalation vulnerability.
An attacker with access to a guest operating system can exploit this issue to gain elevated privileges on affected computers.
Note: This issue was previously discussed in BID 60422 (Xen 'ELF' Parser Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
Xen is prone to a privilege-escalation vulnerability.
An attacker with access to a guest operating system can exploit this issue to gain elevated privileges on affected computers.
Note: This issue was previously discussed in BID 60422 (Xen 'ELF' Parser Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen CVE-2013-2195 Pointer Dereference Privilege Escalation Vulnerability
References:
References:
- Security vulnerability in Citrix XenServer PV guest kernel loading could result (Citrix)
- Xen Project Homepage (Xen Project)
- Xen Security Advisory 55 - Multiple vulnerabilities in libelf PV kernel handling (Xen.org security team)
- Xen Security Advisory 55 - Multiple vulnerabilities in libelf PV kernel handling (Xen.org security team)
- xen: Multiple vulnerabilities in libelf PV kernel handling (Red Hat)
- Citrix XenClient XT Multiple Security Updates (Citrix)
- [Xen-devel] Xen Security Advisory 55 - Multiple vulnerabilities in libelf PV ker (Xen)