Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/59293 | vdb entry |
http://secunia.com/advisories/55082 | third party advisory |
http://www.openwall.com/lists/oss-security/2013/04/18/9 | mailing list |
http://security.gentoo.org/glsa/glsa-201309-24.xml | vendor advisory |
http://www.debian.org/security/2013/dsa-2666 | vendor advisory |
http://www.securitytracker.com/id/1028459 | vdb entry |
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104537.html | vendor advisory |