SB2013041807 - Permissions, Privileges, and Access Controls in xen (Alpine package)
Published: April 18, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-1919)
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Remediation
Install update from vendor's website.