Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201407-03 ] Xen: Multiple Vunlerabilities
Date: Wed, 16 Jul 2014 16:46:02
Message-Id: 53C6ACEF.3000003@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201407-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Xen: Multiple Vunlerabilities
9 Date: July 16, 2014
10 Bugs: #440768, #484478, #486354, #497082, #497084, #497086,
11 #499054, #499124, #500528, #500530, #500536, #501080,
12 #501906, #505714, #509054, #513824
13 ID: 201407-03
14
15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
16
17 Synopsis
18 ========
19
20 Multiple vulnerabilities have been found in Xen, the worst of which
21 could lead to arbitrary code execution.
22
23 Background
24 ==========
25
26 Xen is a bare-metal hypervisor.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 app-emulations/xen < 4.3.2-r4 >= 4.3.2-r4
35 *>= 4.2.4-r4
36 2 app-emulations/xen-tools
37 < 4.3.2-r5 >= 4.3.2-r5
38 *>= 4.2.4-r6
39 3 app-emulations/xen-pvgrub
40 < 4.3.2 *>= 4.3.2
41 *>= 4.2.4
42 -------------------------------------------------------------------
43 3 affected packages
44
45 Description
46 ===========
47
48 Multiple vulnerabilities have been discovered in Xen. Please review the
49 CVE identifiers referenced below for details.
50
51 Impact
52 ======
53
54 A remote attacker can utilize multiple vectors to execute arbitrary
55 code, cause Denial of Service, or gain access to data on the host.
56
57 Workaround
58 ==========
59
60 There is no known workaround at this time.
61
62 Resolution
63 ==========
64
65 All Xen 4.3 users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot --verbose ">=app-emulations/xen-4.3.2-r2"
69
70 All Xen 4.2 users should upgrade to the latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot --verbose ">=app-emulations/xen-4.2.4-r2"
74
75 All xen-tools 4.3 users should upgrade to the latest version:
76
77 # emerge --sync
78 # emerge --ask --oneshot -v ">=app-emulations/xen-tools-4.3.2-r2"
79
80 All xen-tools 4.2 users should upgrade to the latest version:
81
82 # emerge --sync
83 # emerge --ask --oneshot -v ">=app-emulations/xen-tools-4.2.4-r2"
84
85 All Xen PVGRUB 4.3 users should upgrade to the latest version:
86
87 # emerge --sync
88 # emerge --ask --oneshot -v ">=app-emulations/xen-pvgrub-4.3.2"
89
90 All Xen PVGRUB 4.2 users should upgrade to the latest version:
91
92 # emerge --sync
93 # emerge --ask --oneshot -v ">=app-emulations/xen-pvgrub-4.2.4"
94
95 References
96 ==========
97
98 [ 1 ] CVE-2013-1442
99 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1442
100 [ 2 ] CVE-2013-4329
101 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4329
102 [ 3 ] CVE-2013-4355
103 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4355
104 [ 4 ] CVE-2013-4356
105 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4356
106 [ 5 ] CVE-2013-4361
107 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4361
108 [ 6 ] CVE-2013-4368
109 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4368
110 [ 7 ] CVE-2013-4369
111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4369
112 [ 8 ] CVE-2013-4370
113 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4370
114 [ 9 ] CVE-2013-4371
115 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4371
116 [ 10 ] CVE-2013-4375
117 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4375
118 [ 11 ] CVE-2013-4416
119 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4416
120 [ 12 ] CVE-2013-4494
121 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4494
122 [ 13 ] CVE-2013-4551
123 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4551
124 [ 14 ] CVE-2013-4553
125 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4553
126 [ 15 ] CVE-2013-4554
127 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4554
128 [ 16 ] CVE-2013-6375
129 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6375
130 [ 17 ] CVE-2013-6400
131 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6400
132 [ 18 ] CVE-2013-6885
133 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6885
134 [ 19 ] CVE-2013-6885
135 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6885
136 [ 20 ] CVE-2014-1642
137 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1642
138 [ 21 ] CVE-2014-1666
139 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1666
140 [ 22 ] CVE-2014-1891
141 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1891
142 [ 23 ] CVE-2014-1892
143 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1892
144 [ 24 ] CVE-2014-1893
145 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1893
146 [ 25 ] CVE-2014-1894
147 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1894
148 [ 26 ] CVE-2014-1895
149 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1895
150 [ 27 ] CVE-2014-1896
151 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1896
152 [ 28 ] CVE-2014-2599
153 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2599
154 [ 29 ] CVE-2014-3124
155 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3124
156 [ 30 ] CVE-2014-4021
157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4021
158
159 Availability
160 ============
161
162 This GLSA and any updates to it are available for viewing at
163 the Gentoo Security Website:
164
165 http://security.gentoo.org/glsa/glsa-201407-03.xml
166
167 Concerns?
168 =========
169
170 Security is a primary focus of Gentoo Linux and ensuring the
171 confidentiality and security of our users' machines is of utmost
172 importance to us. Any security concerns should be addressed to
173 security@g.o or alternatively, you may file a bug at
174 https://bugs.gentoo.org.
175
176 License
177 =======
178
179 Copyright 2014 Gentoo Foundation, Inc; referenced text
180 belongs to its owner(s).
181
182 The contents of this document are licensed under the
183 Creative Commons - Attribution / Share Alike license.
184
185 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature