Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4554
HistoryDec 24, 2013 - 12:00 a.m.

CVE-2013-4554

2013-12-2400:00:00
ubuntu.com
ubuntu.com
10

5.2 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

0.001 Low

EPSS

Percentile

26.7%

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and
4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls,
which allows local guest users to gain privileges via a crafted application
running in ring 1 or 2.

Notes

Author Note
mdeslaur This is XSA-76 Xen 3.0.3 and later are affected
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchxen< 4.1.5-0ubuntu0.12.04.2UNKNOWN
ubuntu12.10noarchxen< 4.1.5-0ubuntu0.12.10.2UNKNOWN
ubuntu13.04noarchxen< 4.2.2-0ubuntu0.13.04.3UNKNOWN
ubuntu13.10noarchxen< 4.3.0-1ubuntu1.2UNKNOWN

5.2 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:S/C:P/I:P/A:P

0.001 Low

EPSS

Percentile

26.7%