Release date:
Updated on:
Affected Systems:
XenSource Xen 4.3.x
XenSource Xen 4.2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63625
CVE (CAN) ID: CVE-2013-4551
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
Xen 4.2.x and 4.3.x have errors when imitating VMLAUNCH and VMRESUME commands. Successful exploitation can cause host system crash. Successful exploitation of this vulnerability requires the HVM client to run on the VMX hardware.
<* Source: Jeff Zimmerman
Link: http://www.securelist.com/en/advisories/55398
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lists.xen.org/archives/html/xen-announce
Http://www.openwall.com/lists/oss-security/2013/11/08/4