Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201810-06 ] Xen: Multiple vulnerabilities
Date: Tue, 30 Oct 2018 21:02:27
Message-Id: a562bede-0603-448a-6161-88052ec96c31@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201810-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Xen: Multiple vulnerabilities
9 Date: October 30, 2018
10 Bugs: #643350, #655188, #655544, #659442
11 ID: 201810-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Xen, the worst of which
19 could cause a Denial of Service condition.
20
21 Background
22 ==========
23
24 Xen is a bare-metal hypervisor.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-emulation/xen < 4.10.1-r2 >= 4.10.1-r2
33 2 app-emulation/xen-tools < 4.10.1-r2 >= 4.10.1-r2
34 -------------------------------------------------------------------
35 2 affected packages
36
37 Description
38 ===========
39
40 Multiple vulnerabilities have been discovered in Xen. Please review the
41 referenced CVE identifiers for details.
42
43 Impact
44 ======
45
46 A local attacker could cause a Denial of Service condition or disclose
47 sensitive information.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Xen users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.10.1-r2"
61
62 All Xen tools users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot -v ">=app-emulation/xen-tools-4.10.1-r2"
66
67 References
68 ==========
69
70 [ 1 ] CVE-2017-5715
71 https://nvd.nist.gov/vuln/detail/CVE-2017-5715
72 [ 2 ] CVE-2017-5753
73 https://nvd.nist.gov/vuln/detail/CVE-2017-5753
74 [ 3 ] CVE-2017-5754
75 https://nvd.nist.gov/vuln/detail/CVE-2017-5754
76 [ 4 ] CVE-2018-10471
77 https://nvd.nist.gov/vuln/detail/CVE-2018-10471
78 [ 5 ] CVE-2018-10472
79 https://nvd.nist.gov/vuln/detail/CVE-2018-10472
80 [ 6 ] CVE-2018-10981
81 https://nvd.nist.gov/vuln/detail/CVE-2018-10981
82 [ 7 ] CVE-2018-10982
83 https://nvd.nist.gov/vuln/detail/CVE-2018-10982
84 [ 8 ] CVE-2018-12891
85 https://nvd.nist.gov/vuln/detail/CVE-2018-12891
86 [ 9 ] CVE-2018-12892
87 https://nvd.nist.gov/vuln/detail/CVE-2018-12892
88 [ 10 ] CVE-2018-12893
89 https://nvd.nist.gov/vuln/detail/CVE-2018-12893
90 [ 11 ] CVE-2018-15468
91 https://nvd.nist.gov/vuln/detail/CVE-2018-15468
92 [ 12 ] CVE-2018-15469
93 https://nvd.nist.gov/vuln/detail/CVE-2018-15469
94 [ 13 ] CVE-2018-15470
95 https://nvd.nist.gov/vuln/detail/CVE-2018-15470
96 [ 14 ] CVE-2018-3620
97 https://nvd.nist.gov/vuln/detail/CVE-2018-3620
98 [ 15 ] CVE-2018-3646
99 https://nvd.nist.gov/vuln/detail/CVE-2018-3646
100 [ 16 ] CVE-2018-5244
101 https://nvd.nist.gov/vuln/detail/CVE-2018-5244
102 [ 17 ] CVE-2018-7540
103 https://nvd.nist.gov/vuln/detail/CVE-2018-7540
104 [ 18 ] CVE-2018-7541
105 https://nvd.nist.gov/vuln/detail/CVE-2018-7541
106 [ 19 ] CVE-2018-7542
107 https://nvd.nist.gov/vuln/detail/CVE-2018-7542
108
109 Availability
110 ============
111
112 This GLSA and any updates to it are available for viewing at
113 the Gentoo Security Website:
114
115 https://security.gentoo.org/glsa/201810-06
116
117 Concerns?
118 =========
119
120 Security is a primary focus of Gentoo Linux and ensuring the
121 confidentiality and security of our users' machines is of utmost
122 importance to us. Any security concerns should be addressed to
123 security@g.o or alternatively, you may file a bug at
124 https://bugs.gentoo.org.
125
126 License
127 =======
128
129 Copyright 2018 Gentoo Foundation, Inc; referenced text
130 belongs to its owner(s).
131
132 The contents of this document are licensed under the
133 Creative Commons - Attribution / Share Alike license.
134
135 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature