Novell Home

CVE-2013-4329

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-4329 at MITRE

Description

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.

NVD CVSS v2 Base Score: 6.5 (AV:A/AC:H/Au:S/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 839618, 840592

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SLE 11 SP2 DEBUGINFO
  • xen-debuginfo >= 4.1.6_02-0.5.1
  • xen-debugsource >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Software Development Kit 11 SP2
  • xen-devel >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-pae >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Server 11 SP2 for VMware
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen >= 4.1.6_02-0.5.1
  • xen-doc-html >= 4.1.6_02-0.5.1
  • xen-doc-pdf >= 4.1.6_02-0.5.1
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-libs-32bit >= 4.1.6_02-0.5.1
  • xen-tools >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SLE 11 SP1 DEBUGINFO
  • xen-debuginfo >= 4.0.3_21548_16-0.5.1
  • xen-debugsource >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963

List of products where fixes are in QA

© 2014 Novell