~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
Candidate: CVE-2013-0154
PublicDate: 2013-01-11
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0154
 http://xforce.iss.net/xforce/xfdb/80977
 http://www.securitytracker.com/id?1027937
 http://www.openwall.com/lists/oss-security/2013/01/04/2
 http://seclists.org/oss-sec/2013/q1/att-17/xsa37-4_2.patch
 http://osvdb.org/88913
Description:
 The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging
 is enabled, allows local PV or HVM guest administrators to cause a denial
 of service (assertion failure and hypervisor crash) via unspecified vectors
 related to a hypercall.
Ubuntu-Description:
Notes:
 mdeslaur> hypervisor packages are in universe. For
 mdeslaur> issues in the hypervisor, add appropriate
 mdeslaur> tags to each section, ex:
 mdeslaur> Tags_xen: universe-binary
 jdstrand> only affect Xen 4.2, and only when debugging enabled. Debugging is
  not enabled in Ubuntu 13.04.
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_xen-3.1:
upstream_xen-3.1: needs-triage
hardy_xen-3.1: ignored (reached end-of-life)
lucid_xen-3.1: DNE
oneiric_xen-3.1: DNE
precise_xen-3.1: DNE
quantal_xen-3.1: DNE
devel_xen-3.1: DNE

Patches_xen-3.2:
upstream_xen-3.2: needs-triage
hardy_xen-3.2: ignored (reached end-of-life)
lucid_xen-3.2: DNE
oneiric_xen-3.2: DNE
precise_xen-3.2: DNE
quantal_xen-3.2: DNE
devel_xen-3.2: DNE

Patches_xen-3.3:
upstream_xen-3.3: needs-triage
hardy_xen-3.3: DNE
lucid_xen-3.3: not-affected
oneiric_xen-3.3: DNE
precise_xen-3.3: DNE
quantal_xen-3.3: DNE
devel_xen-3.3: DNE

Patches_xen:
upstream_xen: 
hardy_xen: DNE
lucid_xen: DNE
oneiric_xen: not-affected
precise_xen: not-affected
quantal_xen: not-affected (4.1.3-3ubuntu1.2)
devel_xen: not-affected