Novell Home

CVE-2013-2211

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-2211 at MITRE

Description

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.

NVD CVSS v2 Base Score: 7.4 (AV:A/AC:M/Au:S/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 823608

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SLE 11 SP2 DEBUGINFO
  • xen-debuginfo >= 4.1.6_02-0.5.1
  • xen-debugsource >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Software Development Kit 11 SP2
  • xen-devel >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-pae >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Server 11 SP2 for VMware
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen >= 4.1.6_02-0.5.1
  • xen-doc-html >= 4.1.6_02-0.5.1
  • xen-doc-pdf >= 4.1.6_02-0.5.1
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-libs-32bit >= 4.1.6_02-0.5.1
  • xen-tools >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SLE 11 SP3 DEBUGINFO
  • xen-debuginfo >= 4.2.2_06-0.7.1
  • xen-debugsource >= 4.2.2_06-0.7.1
Builds
SAT Patch Nr: 8063
SUSE Linux Enterprise Software Development Kit 11 SP3
  • xen-devel >= 4.2.2_06-0.7.1
Builds
SAT Patch Nr: 8063
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen-kmp-default >= 4.2.2_06_3.0.82_0.7-0.7.1
  • xen-kmp-pae >= 4.2.2_06_3.0.82_0.7-0.7.1
  • xen-libs >= 4.2.2_06-0.7.1
  • xen-tools-domU >= 4.2.2_06-0.7.1
Builds
SAT Patch Nr: 8063
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen >= 4.2.2_06-0.7.1
  • xen-doc-html >= 4.2.2_06-0.7.1
  • xen-doc-pdf >= 4.2.2_06-0.7.1
  • xen-kmp-default >= 4.2.2_06_3.0.82_0.7-0.7.1
  • xen-libs >= 4.2.2_06-0.7.1
  • xen-libs-32bit >= 4.2.2_06-0.7.1
  • xen-tools >= 4.2.2_06-0.7.1
  • xen-tools-domU >= 4.2.2_06-0.7.1
Builds
SAT Patch Nr: 8063
SLE 11 SP1 DEBUGINFO
  • xen-debuginfo >= 4.0.3_21548_16-0.5.1
  • xen-debugsource >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963

List of products where fixes are in QA

© 2014 Novell