Oval Definition:oval:com.redhat.rhsa:def:20130599
Revision Date:2013-03-06Version:636
Title:RHSA-2013:0599: xen security update (Important)
Description:The xen packages contain administration tools and the xend service for managing the kernel-xen kernel for virtualization on Red Hat Enterprise Linux.

  • A flaw was found in the way QEMU emulated the e1000 network interface card when the host was configured to accept jumbo network frames, and a fully-virtualized guest using the e1000 emulated driver was not. A remote attacker could use this flaw to crash the guest or, potentially, execute arbitrary code with root privileges in the guest. (CVE-2012-6075)

    All users of xen are advised to upgrade to these updated packages, which correct this issue. After installing the updated packages, all running fully-virtualized guests must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-6075
    RHSA-2013:0599
    RHSA-2013:0599-00
    RHSA-2013:0599-01
    RHSA-2013:0599-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • xen is earlier than 0:3.0.3-142.el5_9.2
  • AND xen is signed with Red Hat redhatrelease2 key
  • xen-devel is earlier than 0:3.0.3-142.el5_9.2
  • AND xen-devel is signed with Red Hat redhatrelease2 key
  • xen-libs is earlier than 0:3.0.3-142.el5_9.2
  • AND xen-libs is signed with Red Hat redhatrelease2 key
  • BACK