Citrix XenServer Multiple Security Updates (CTX140984)

Published: 2014-12-18 16:37:46
CVE Author: NIST National Vulnerability Database

CVSS Base Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Detection Method:
Check the installed hotfixes

Recommendations:
Apply the hotfix referenced in the advisory.

Summary:
A number of security vulnerabilities have been identified in Citrix XenServer. These vulnerabilities affect all currently supported versions of Citrix XenServer up to and including Citrix XenServer 6.2 Service Pack 1. The following vulnerabilities have been addressed: - CVE-2014-4021: Citrix XenServer potential guest information leak through hypervisor page reuse - CVE-2014-4947: Buffer overflow in Citrix XenServer HVM graphics console support - CVE-2014-4948: Citrix XenServer guest denial of service and information leak through guest VHD modification

Affected Versions:
Citrix XenServer 6.2 Service Pack 1, Citrix XenServer 6.1, Citrix XenServer 6.0.2 Citrix XenServer 6.0.0

Solution Type:
Vendor Patch

Detection Type:
Linux Distribution Package

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2014-4021
https://nvd.nist.gov/vuln/detail/CVE-2014-4947
https://nvd.nist.gov/vuln/detail/CVE-2014-4948

CVE Analysis

https://www.mageni.net/cve/CVE-2014-4021
https://www.mageni.net/cve/CVE-2014-4947
https://www.mageni.net/cve/CVE-2014-4948

SecurityFocus Bugtraq ID:

https://www.securityfocus.com/bid/68070
https://www.securityfocus.com/bid/68659
https://www.securityfocus.com/bid/68660

References:

http://support.citrix.com/article/CTX140984

Severity
High
CVSS Score
10.0
Published
2014-12-18
Modified
2018-10-12
Category
Citrix Xenserver Local Security Checks

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.