SB2016091411 - Access control error in xen (Alpine package)



SB2016091411 - Access control error in xen (Alpine package)

Published: September 14, 2016

Security Bulletin ID SB2016091411
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Access control error (CVE-ID: CVE-2016-7093)

The vulnerability allows local user to get elevated privileges on the host system.

The vulnerability exists due to instruction pointer truncation error that allows a local administrative user on the HVM guest system to gain priviliges on the target system.

Successful exploitation of this vulnerability will result in gaining elevated privileges by the guest attacker.

Remediation

Install update from vendor's website.