SB2017061529 - Privilege escalation in xen (Alpine package)
Published: June 15, 2017
Security Bulletin ID
SB2017061529
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2017-8905)
The vulnerability allows a local attacker to gain elevated privileges on the target system.The weakness exists due to insufficient validation of user-supplied input. A local attacker can use a failsafe callback to modify part of a physical memory page, execute arbitrary code on the host OS with elevated privileges.
Successful exploitation of the vulnerability may result in privilege escalation.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=379c5299d65499022d1f9338b6042ef5f6008b52
- https://git.alpinelinux.org/aports/commit/?id=c12d6f2d2fc4ffae930a97f25ade837b85e48808
- https://git.alpinelinux.org/aports/commit/?id=7f989732c4db2c7fa917bf58b0dd9b931dc2b9a5
- https://git.alpinelinux.org/aports/commit/?id=231b8648691a0c1f456d8f87e56bd6480fb4a0bc