Information disclosure in Xen - CVE-2018-10472

 

Information disclosure in Xen - CVE-2018-10472

Published: May 9, 2018 / Updated: May 10, 2018


Vulnerability identifier: #VU12543
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10472
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.

The weakness exists in certain configurations due to improper information control. An adjacent attacker can read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.


Affected software

Xen
Debian Linux
Gentoo Linux
SUSE Linux
Fedora
xen (Alpine package)
xen

How to mitigate CVE-2018-10472

Install update from vendor's website.

xen (Alpine package) - update to 4.6.6-r5
xen - addressed in versions 4.8.3-4.fc26, 4.9.2-2.fc27, 4.10.0-9.fc28

External References

Related Security Bulletins