[SECURITY] Fedora 18 Update: xen-4.2.0-6.fc18

updates at fedoraproject.org updates at fedoraproject.org
Wed Dec 12 00:16:38 UTC 2012


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-19652
2012-12-04 21:01:10
--------------------------------------------------------------------------------

Name        : xen
Product     : Fedora 18
Version     : 4.2.0
Release     : 6.fc18
URL         : http://xen.org/
Summary     : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

A guest can cause xen to crash [XSA-26, CVE-2012-5510] (#883082)
An HVM guest can cause xen to run slowly or crash [XSA-27, CVE-2012-5511]
(#883084)
A PV guest can cause xen to crash and might be able escalate privileges
[XSA-29, CVE-2012-5513] (#883088)
An HVM guest can cause xen to hang [XSA-30, CVE-2012-5514] (#883091)
A guest can cause xen to hang [XSA-31, CVE-2012-5515] (#883092)
A PV guest can cause xen to crash and might be able escalate privileges
[XSA-32, CVE-2012-5525] (#883094)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #877358 - CVE-2012-5510 kernel: xen: Grant table version switch list corruption vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=877358
  [ 2 ] Bug #877365 - CVE-2012-5511 kernel: xen: several HVM operations do not validate the range of their inputs
        https://bugzilla.redhat.com/show_bug.cgi?id=877365
  [ 3 ] Bug #877391 - CVE-2012-5513 kernel: xen: XENMEM_exchange may overwrite hypervisor memory
        https://bugzilla.redhat.com/show_bug.cgi?id=877391
  [ 4 ] Bug #877404 - CVE-2012-5525 kernel: xen: several hypercalls do not validate input GFNs
        https://bugzilla.redhat.com/show_bug.cgi?id=877404
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xen' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list