Citrix XenServer Security Update for CVE-2015-5307 and CVE-2015-8104 (CTX202583)

Published: 2015-11-26 11:28:16
CVE Author: NIST National Vulnerability Database

CVSS Base Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C

Detection Method:
Check the installed hotfixes

Recommendations:
Apply the hotfix referenced in the advisory.

Summary:
A security vulnerability has been identified in Citrix XenServer that may allow a malicious administrator of an HVM guest VM to crash the host. This vulnerability affects all currently supported versions of Citrix XenServer up to and including Citrix XenServer 6.5 Service Pack 1.

Affected Versions:
Citrix XenServer up to and including Citrix XenServer 6.5 Service Pack 1.

Solution Type:
Vendor Patch

Detection Type:
Linux Distribution Package

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2015-5307
https://nvd.nist.gov/vuln/detail/CVE-2015-8104

References:

http://support.citrix.com/article/CTX202583

Severity
Medium
CVSS Score
4.9

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.