SB2013011103 - Buffer overflow in xen (Alpine package)
Published: January 11, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-2072)
The vulnerability allows a remote #AU# to execute arbitrary code.
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=13e7303be19a003b85e73795409e1bcb7bfa9666
- https://git.alpinelinux.org/aports/commit/?id=98f79460df6cf28f150e4bca1a7f976d3d0fe331
- https://git.alpinelinux.org/aports/commit/?id=9e709edc63f75e55ae48fc0050ce265c343767b8
- https://git.alpinelinux.org/aports/commit/?id=f8281e3365bc2fc99aa6232266c067585a0b83a9