CVE-2013-2078: Input Validation
Published Aug 14, 2013
·Updated
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
Affected Software
12 affected components
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
Event History
Aug 14, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2078?
CVE-2013-2078 has a medium severity rating as it allows local users to cause a denial of service through a hypervisor crash.
2
How do I fix CVE-2013-2078?
To fix CVE-2013-2078, upgrade to Xen version 4.3.x or later, which addresses this vulnerability.
3
Which versions of Xen are affected by CVE-2013-2078?
CVE-2013-2078 affects Xen versions 4.0.2 through 4.0.4, all 4.1.x versions, and 4.2.x versions.
4
What type of attack does CVE-2013-2078 facilitate?
CVE-2013-2078 facilitates a denial of service attack against the hypervisor via specific XSETBV instruction bit combinations.
5
Can CVE-2013-2078 be exploited remotely?
CVE-2013-2078 cannot be exploited remotely as it requires local access by PV guest users.