From f70a1bfc721336d4fc7dfb711c2f518a6b18cf16 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Wed, 30 Sep 2020 17:27:54 +0100 Subject: gentoo resync : 30.09.2020 --- metadata/glsa/glsa-202009-14.xml | 61 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 metadata/glsa/glsa-202009-14.xml (limited to 'metadata/glsa/glsa-202009-14.xml') diff --git a/metadata/glsa/glsa-202009-14.xml b/metadata/glsa/glsa-202009-14.xml new file mode 100644 index 000000000000..e7f29aeae16a --- /dev/null +++ b/metadata/glsa/glsa-202009-14.xml @@ -0,0 +1,61 @@ + + + + Xen: Buffer overflow + A buffer overflow in Xen might allow remote attacker(s) to execute + arbitrary code. + + xen + 2020-09-29 + 2020-09-29 + 738040 + local, remote + + + 4.13.1-r3 + 4.13.1-r3 + + + 4.13.1-r3 + 4.13.1-r3 + + + +

Xen is a bare-metal hypervisor.

+
+ +

An out-of-bounds read/write access issue was found in the USB emulator + when using QEMU. +

+
+ +

A remote attacker could possibly execute arbitrary code with the + privileges of the process or cause a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Xen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.13.1-r3" + + +

All Xen tools users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=app-emulation/xen-tools-4.13.1-r3" + +
+ + CVE-2020-14364 + XSA-335 + + sam_c + sam_c +
-- cgit v1.2.3