Buffer overflow in Xen - CVE-2013-1918
Published: May 14, 2013 / Updated: July 28, 2020
Vulnerability identifier: #VU32656
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1918
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
Affected software
Xen
Gentoo Linux
SUSE Linux
xen (Alpine package)
app-emulation/xen
app-emulation/xen-pvgrub
app-emulation/xen-tools
Gentoo Linux
SUSE Linux
xen (Alpine package)
app-emulation/xen
app-emulation/xen-pvgrub
app-emulation/xen-tools
How to mitigate CVE-2013-1918
Install update from vendor's website.
xen (Alpine package) - update to 4.1.4-r6
app-emulation/xen - update to 4.2.2-r1
app-emulation/xen-pvgrub - update to 4.2.2-r1
app-emulation/xen-tools - update to 4.2.2-r3
app-emulation/xen - update to 4.2.2-r1
app-emulation/xen-pvgrub - update to 4.2.2-r1
app-emulation/xen-tools - update to 4.2.2-r3
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105533.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html
- http://secunia.com/advisories/53187
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- http://www.debian.org/security/2013/dsa-2666
- http://www.openwall.com/lists/oss-security/2013/05/02/8
- http://www.securityfocus.com/bid/59615