Xen 4.5.x and earlier enables certain default backends when emulating...
Vulnerability Description
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2152
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security.gentoo.org/glsa/201504-04
- http://www.securitytracker.com/id/1031919
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.html
- http://www.securityfocus.com/bid/73068
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.html
- http://xenbits.xen.org/xsa/advisory-119.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html
- http://www.securitytracker.com/id/1031806
More from xen
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.