#VU766 Information disclosure in Xen and Oracle VM Server for x86 - CVE-2016-7777

 

#VU766 Information disclosure in Xen and Oracle VM Server for x86 - CVE-2016-7777

Published: October 5, 2016 / Updated: January 10, 2017


Vulnerability identifier: #VU766
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-7777
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Xen
Oracle VM Server for x86
Software vendor:
Xen Project
Oracle

Description

The vulnerability allows a local unprivileged user to obtain potentially sensitive information on the guest system.
The weakness is caused by insufficient access control mechanisms. A local unprivileged user of a guest operating system can trigger the Xen instruction emulator by attempting to execute an invalid opcode and read or modify FPU, MMX, and XMM register state data of another process within the same guest system.
Successful exploitation of the vulnerability leads to register state information disclosure and corruption.

Remediation

Update to version 5 or apply the following patches:

XSA-190 version 4.5.
http://xenbits.xen.org/xsa/xsa190-4.5.patch
XSA-190 version 4.6.
http://xenbits.xen.org/xsa/xsa190-4.6.patch

External links