Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4375
HistoryJan 19, 2014 - 12:00 a.m.

CVE-2013-4375

2014-01-1900:00:00
ubuntu.com
ubuntu.com
12

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:N/I:N/A:P

0.001 Low

EPSS

Percentile

25.1%

The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1,
and qemu 1.1 and other versions, allows local HVM guests to cause a denial
of service (domain grant reference consumption) via unspecified vectors.

Notes

Author Note
jdstrand per upstream, xen 4.2 and later per Xen team, qemu 1.1 and later
mdeslaur per smb, this is only in qemu packages, and we only really use the one in saucy+ This is XSA-71 introduced in c6961b7d38317fd48a8e86a8c2be4b9aeeb71ac0 quantal file location is hw/xen_disk.c
OSVersionArchitecturePackageVersionFilename
ubuntu13.10noarchqemu< 1.5.0+dfsg-3ubuntu5.3UNKNOWN
ubuntu12.10noarchqemu-kvm< 1.2.0+noroms-0ubuntu2.12.10.6UNKNOWN

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:N/I:N/A:P

0.001 Low

EPSS

Percentile

25.1%