Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2078
HistoryAug 14, 2013 - 12:00 a.m.

CVE-2013-2078

2013-08-1400:00:00
ubuntu.com
ubuntu.com
11

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

0.001 Low

EPSS

Percentile

26.7%

Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to
cause a denial of service (hypervisor crash) via certain bit combinations
to the XSETBV instruction.

Notes

Author Note
seth-arnold adding “no-xsave” to supervisor mitigates against the problem
mdeslaur This is XSA-54
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchxen< 4.1.2-2ubuntu2.9UNKNOWN
ubuntu12.10noarchxen< 4.1.3-3ubuntu1.6UNKNOWN
ubuntu13.04noarchxen< 4.2.1-0ubuntu3.2UNKNOWN

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

0.001 Low

EPSS

Percentile

26.7%