5.2

CVE-2013-4494

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xen ≫ Xen Version >= 4.1.0 <= 4.1.6.1
Xen ≫ Xen Version >= 4.2.0 <= 4.2.5
Xen ≫ Xen Version >= 4.3.0 <= 4.3.4
Debian ≫ Debian Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.471
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.2 4.4 6.9
AV:A/AC:M/Au:S/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2014/dsa-3006
Third Party Advisory
http://security.gentoo.org/glsa/glsa-201407-03.xml
Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2013-12/msg00059.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0108.html
Third Party Advisory
http://www.openwall.com/lists/oss-security/2013/11/01/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2013/11/01/3
Third Party Advisory
Mailing List