You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Xen

Sigurnosni nedostaci programskog paketa Xen

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Gentoo Linux Security Advisory GLSA 201710-17
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
https://security.gentoo.org/
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Severity: High
Title: Xen: Multiple vulnerabilities
Date: October 18, 2017
Bugs: #624112, #624116, #624118, #624124, #624128
ID: 201710-17

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Synopsis
========

Multiple vulnerabilities have been found in Xen, the worst of which may
allow local attackers to escalate privileges.

Background
==========

Xen is a bare-metal hypervisor.

Affected packages
=================

——————————————————————-
Package / Vulnerable / Unaffected
——————————————————————-
1 app-emulation/xen < 4.7.3 >= 4.7.3
2 app-emulation/xen-pvgrub
< 4.7.3 >= 4.7.3
3 app-emulation/xen-tools < 4.7.3 >= 4.7.3
——————————————————————-
3 affected packages

Description
===========

Multiple vulnerabilities have been discovered in Xen. Please review the
referenced CVE identifiers for details.

Impact
======

A local attacker could escalate privileges, cause a Denial of Service
condition, obtain sensitive information, or have other unspecified
impacts.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Xen users should upgrade to the latest version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=app-emulation/xen-4.7.3”

All Xen pvgrub users should upgrade to the latest version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=app-emulation/xen-pvgrub-4.7.3”

All Xen Tools users should upgrade to the latest version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=app-emulation/xen-tools-4.7.3”

References
==========

[ 1 ] CVE-2017-10912
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10912
[ 2 ] CVE-2017-10913
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10913
[ 3 ] CVE-2017-10914
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10914
[ 4 ] CVE-2017-10915
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10915
[ 5 ] CVE-2017-10918
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10918
[ 6 ] CVE-2017-10920
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10920
[ 7 ] CVE-2017-10921
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10921
[ 8 ] CVE-2017-10922
https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10922

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/201710-17

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users’ machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2017 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons – Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5—–BEGIN PGP SIGNATURE—–

iQEzBAABCAAdFiEEiDRK3jyVBE/RkymqpRQw84X1dt0FAlnmo4AACgkQpRQw84X1
dt2ldQf9FEtOCpyqmTDN+AYYNW4DaB9ztL99lmOtmbrS2Uv+7zSB7YR4HcAt1mlm
HNN/NN3A8dWEmlPBhRJ7lnSG20WraU8eEIhxm8G/bQCHwieRh2LogUIb0KIOyx/t
yh36pKbZHvDWf0fT+qUBlBZuZAt8HSKfZvetFMGPFnWUdL1VtcKWC0lS31a1z+rI
+xFpXDrE5M1zvbFLRcYCaj0KAeJmSiLO/fKt0qSbrynbJ0GThA92p6Vs1V7OedHI
WlPoWdHUhiHeK2o9XU2XRg9Lwj6svhefQ2pOWgfVjflCnKnxGaxO8+XRi/49erUf
3CTsei0fUVL8C/RgfK6VfrFQxJPnlw==
=+7×2
—–END PGP SIGNATURE—–

Top
More in Preporuke
Nadogradnja za Adobe Flash Player

Adobe je izdao nadogradnju za otklanjanje kritične ranjivosti programskog paketa Adobe Flash Player. Ranjivost je uzrokovana nepravilnom obradom SWF datoteke,...

Close