Release date:
Updated on: 2013-01-22
Affected Systems:
XenSource Xen 2.6.23
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57433
CVE (CAN) ID: CVE-2013-0190
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
Xen 2.6.23 and other versions of the function "xen_failsafe_callback ()" have an error in implementation when handling failed IRET, and local attackers who have access permissions to the client operating system, this vulnerability can be exploited to cause a client operating system crash. To exploit this vulnerability, you must use the ParaVirtual OPerationS (PVOPS) client.
<* Source: Andrew Cooper
Link: http://www.securelist.com/en/advisories/51834
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://xen.xensource.com/