SB2011081201 - Multiple vulnerabilities in Xen
Published: August 12, 2011 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Resource management error (CVE-ID: CVE-2011-3262)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."
2) Input validation error (CVE-ID: CVE-2011-1583)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.
3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-1898)
The vulnerability allows a remote #AU# to execute arbitrary code.
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
Remediation
Install update from vendor's website.
References
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00483.html
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00491.html
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69381
- http://rhn.redhat.com/errata/RHSA-2011-0496.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062112.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062139.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00018.html
- http://theinvisiblethings.blogspot.com/2011/05/following-white-rabbit-software-attacks.html
- http://www.invisiblethingslab.com/resources/2011/Software%20Attacks%20on%20Intel%20VT-d.pdf
- http://xen.1045712.n5.nabble.com/Xen-security-advisory-CVE-2011-1898-VT-d-PCI-passthrough-MSI-td4390298.html
- http://xen.org/download/index_4.0.2.html