LOW · 1.9

CVE-2015-2152

Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access ...

Vulnerability Description

Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.

CVSS Score

1.9

LOW

AV:L/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
XenXen<= 4.5.0
FedoraprojectFedora20

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2152?

CVE-2015-2152 is a vulnerability with a CVSS score of 1.9 (LOW). Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access ...

How severe is CVE-2015-2152?

CVE-2015-2152 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2152?

Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen, Fedoraproject Fedora.