NASLDB: Debian DSA-2531-1 : xen - Denial of Service
General
ID: 61578
Name: Debian DSA-2531-1 : xen – Denial of Service
Summary: Checks dpkg output for the updated package
Credits: –
Classification
Risk: –
CVSS: –
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Debian Local Security Checks
Type: Local
Description
Several denial-of-service vulnerabilities have been discovered in Xen,
the popular virtualization software. The Common Vulnerabilities and
Exposures project identifies the following issues :
– CVE-2012-3432
Guest mode unprivileged code, which has been granted the
privilege to access MMIO regions, may leverage that
access to crash the whole guest. Since this can be used
to crash a client from within, this vulnerability is
considered to have low impact.
– CVE-2012-3433
A guest kernel can cause the host to become unresponsive
for a period of time, potentially leading to a DoS.
Since an attacker with full control in the guest can
impact the host, this vulnerability is considered to
have high impact.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2012-3432
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: 2012/08/18
Plugin Release: 2012/08/20
Plugin
Version: 1.1
Filename: debian_DSA-2531.nasl
Filesize: 3576 bytes
MD5 Hash: daa03fe1bc3633200d9d544cf5059724
Identification: Host/local_checks_enabled
Require Keys: Host/local_checks_enabled", "Host/Debian/release", "Host/Debian/dpkg-l
Dependencies: "ssh_get_info.nasl"
Copyright: This script is© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













