SB2013082902 - Permissions, Privileges, and Access Controls in Xen



SB2013082902 - Permissions, Privileges, and Access Controls in Xen

Published: August 29, 2013 Updated: July 28, 2020

Security Bulletin ID SB2013082902
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-2211)

The vulnerability allows a remote #AU# to execute arbitrary code.

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.


Remediation

Install update from vendor's website.