CVE-2013-2077: Medium severity xen xapi vulnerability
Published Aug 28, 2013
·Updated
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
Affected Software
14 affected components
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
Event History
Aug 28, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2077?
CVE-2013-2077 has a high severity rating due to its potential to cause a denial of service and hypervisor crash.
2
How do I fix CVE-2013-2077?
To fix CVE-2013-2077, upgrade to a version of Xen that addresses this vulnerability, specifically versions beyond 4.2.2.
3
Who is affected by CVE-2013-2077?
CVE-2013-2077 affects local PV guest users on Xen versions 4.0.x, 4.1.x, and 4.2.x.
4
What kind of attacks can exploit CVE-2013-2077?
CVE-2013-2077 can be exploited through unspecified vectors that trigger unhandled exceptions in the hypervisor.
5
When was CVE-2013-2077 discovered?
CVE-2013-2077 was publicly disclosed in 2013.