CVE-2013-4369: Null Pointer Dereference
Published Oct 17, 2013
·Updated
The xluvifparserate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
Affected Software
5 affected components
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
Event History
Oct 17, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4369?
CVE-2013-4369 has a medium severity rating due to its potential for denial of service.
2
How do I fix CVE-2013-4369?
To fix CVE-2013-4369, update your Xen installation to a version later than 4.3.0.
3
What versions of Xen are affected by CVE-2013-4369?
CVE-2013-4369 affects Xen versions 4.2.x and 4.3.x.
4
What is the nature of the vulnerability in CVE-2013-4369?
CVE-2013-4369 is a denial of service vulnerability caused by a NULL pointer dereference.
5
Can local users exploit CVE-2013-4369?
Yes, local users can exploit CVE-2013-4369 by using the '@' character in the VIF rate configuration.