Input validation error in Debian products - CVE-2014-8595

 

Input validation error in Debian products - CVE-2014-8595

Published: November 19, 2014 / Updated: August 9, 2020


Vulnerability identifier: #VU41090
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8595
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.


Affected software

Xen
Opensuse
Debian Linux
Gentoo Linux
SUSE Linux
Fedora
xen

How to mitigate CVE-2014-8595

Install update from vendor's website.

xen - addressed in versions 4.4.1-7.fc21, 4.4.1-8.fc21, 4.4.1-9.fc21

External References

Related Security Bulletins