CVE-2016-4962: Medium severity oracle vm server vulnerability
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4962?
CVE-2016-4962 has a severity rating that may lead to a denial of service and potential host OS privilege escalation.
How do I fix CVE-2016-4962?
To fix CVE-2016-4962, users should upgrade to the latest patched version of Xen or Oracle VM Server.
What systems are affected by CVE-2016-4962?
CVE-2016-4962 affects specific versions of Xen including 4.3.x, 4.4.x, 4.5.x, and 4.6.x, as well as Oracle VM Server versions 3.3 and 3.4.
What type of vulnerability is CVE-2016-4962?
CVE-2016-4962 is a local denial of service and privilege escalation vulnerability.
Can CVE-2016-4962 be exploited remotely?
No, CVE-2016-4962 requires local OS guest administrator access to exploit.