CVE-2013-1919: Medium severity xen xapi vulnerability
Published May 13, 2013
·Updated
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Affected Software
9 affected components
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
Event History
May 13, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1919?
CVE-2013-1919 is considered to have a moderate severity level due to its ability to cause a denial of service.
2
How do I fix CVE-2013-1919?
To address CVE-2013-1919, upgrade to the latest version of Xen that has implemented the necessary security patches.
3
What are the affected versions in CVE-2013-1919?
CVE-2013-1919 affects Xen versions 4.1.0 through 4.1.5 and 4.2.0 through 4.2.2.
4
Can CVE-2013-1919 be exploited remotely?
No, CVE-2013-1919 can only be exploited locally by stub domain clients.
5
What kind of attacks does CVE-2013-1919 allow?
CVE-2013-1919 allows local attackers to gain unauthorized access to IRQs, leading to potential denial of service.