Vulnerability Name:

CVE-2014-1642 (CCN-90649)

Assigned:2014-01-23
Published:2014-01-23
Updated:2018-01-03
Summary:The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.4 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-1642

Source: FEDORA
Type: UNKNOWN
FEDORA-2014-1559

Source: FEDORA
Type: UNKNOWN
FEDORA-2014-1552

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0373

Source: CCN
Type: XSA-83
Xen Security Advisory 83 (CVE-2014-1642) - Out-of-memory condition yielding memory corruption during IRQ setup

Source: OSVDB
Type: UNKNOWN
102406

Source: CCN
Type: SA56557
Xen "pirq_guest_bind()" IRQ Setup Double Free Vulnerability

Source: SECUNIA
Type: Vendor Advisory
56557

Source: GENTOO
Type: UNKNOWN
GLSA-201407-03

Source: MLIST
Type: UNKNOWN
[oss-security] 20140123 Xen Security Advisory 83 (CVE-2014-1642) - Out-of-memory condition yielding memory corruption during IRQ setup

Source: BID
Type: UNKNOWN
65097

Source: CCN
Type: BID-65097
Xen Use After Free Memory Corruption Vulnerability

Source: SECTRACK
Type: UNKNOWN
1029679

Source: CONFIRM
Type: Vendor Advisory
http://xenbits.xen.org/xsa/advisory-83.html

Source: XF
Type: UNKNOWN
xen-irq-cve20141642-code-exec(90649)

Source: XF
Type: UNKNOWN
xen-irq-cve20141642-code-exec(90649)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-1642

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xen:xen:4.2.0:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:4.2.2:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:4.2.3:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:4.3.0:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:4.3.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xensource:xen:4.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20141642
    V
    CVE-2014-1642
    2022-05-20
    oval:org.opensuse.security:def:30284
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:55977
    P
    Security update for xen (Moderate)
    2021-11-29
    oval:org.opensuse.security:def:34595
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:56089
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:57520
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:31687
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:34538
    P
    Security update for postgresql12 (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:56051
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:55220
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:30210
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:30199
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:34440
    P
    Security update for curl (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:57446
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:30198
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:55885
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:31649
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:55777
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35739
    P
    libapr1-1.3.3-11.18.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:28857
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:35698
    P
    foomatic-filters-3.0.2-269.35.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:54809
    P
    icu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27139
    P
    gpgme on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27419
    P
    imlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27909
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:34208
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:27834
    P
    Security update for mono-core (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56170
    P
    Security update for dbus-1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28140
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30416
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:34951
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:26536
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30859
    P
    Security update for e2fsprogs
    2020-12-01
    oval:org.opensuse.security:def:54647
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27037
    P
    syslog-ng on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27407
    P
    gdk-pixbuf on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55326
    P
    m4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27236
    P
    lxc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27693
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:34304
    P
    Security update for quagga (Low)
    2020-12-01
    oval:org.opensuse.security:def:28087
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34844
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26461
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:30649
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35060
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26802
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30967
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:55047
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27178
    P
    libcgroup1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27483
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34209
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27985
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28184
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30505
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34990
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:26664
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54669
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27090
    P
    bash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27408
    P
    ghostscript-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55492
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27874
    P
    Security update for rubygem-activerecord-2_3 and rubygem-activesupport-2_3
    2020-12-01
    oval:org.opensuse.security:def:27750
    P
    Security update for gd
    2020-12-01
    oval:org.opensuse.security:def:28126
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34902
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26472
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:30804
    P
    Security update for cifs-utils (Important)
    2020-12-01
    oval:org.opensuse.security:def:54646
    P
    patch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26886
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31011
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27192
    P
    libksba on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27611
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34220
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28038
    P
    Security update for cracklib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34685
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:28822
    P
    Security update for python-lxml
    2020-12-01
    oval:org.opensuse.security:def:26460
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:30562
    P
    Security update for pcp
    2020-12-01
    oval:org.opensuse.security:def:35016
    P
    Security update for graphviz (Low)
    2020-12-01
    oval:org.opensuse.security:def:26745
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30947
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.mitre.oval:def:25390
    P
    SUSE-SU-2014:0373-1 -- Security update for Xen
    2014-09-08
    oval:org.opensuse.security:def:80154
    P
    Security update for Xen
    2014-02-27
    oval:com.ubuntu.precise:def:20141642000
    V
    CVE-2014-1642 on Ubuntu 12.04 LTS (precise) - medium.
    2014-01-26
    BACK
    xen xen 4.2.0
    xen xen 4.2.1
    xen xen 4.2.2
    xen xen 4.2.3
    xen xen 4.3.0
    xen xen 4.3.1
    xensource xen 4.2