Vulnerability Name:

CVE-2014-1894 (CCN-91312)

Assigned:2014-02-10
Published:2014-02-10
Updated:2017-01-07
Summary:Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1891, CVE-2014-1892, and CVE-2014-1893.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.2 Medium (CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C)
3.8 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-189
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-1894

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0372

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0373

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0446

Source: CCN
Type: XSA-84
Xen Security Advisory 84 (CVE-2014-1891, CVE-2014-1892, CVE-2014-1893, CVE-2014-1894) - integer overflow in several XSM/Flask hypercalls

Source: GENTOO
Type: UNKNOWN
GLSA-201407-03

Source: MLIST
Type: UNKNOWN
[oss-security] 20140207 Re: Xen Security Advisory 84 - integer overflow in several XSM/Flask hypercalls

Source: MLIST
Type: UNKNOWN
[oss-security] 20140207 Re: Xen Security Advisory 84 - integer overflow in several XSM/Flask hypercalls

Source: MLIST
Type: UNKNOWN
[oss-security] 20140210 Xen Security Advisory 84 (CVE-2014-1891,CVE-2014-1892,CVE-2014-1893,CVE-2014-1894) - integer overflow in several XSM/Flask hypercalls

Source: CCN
Type: BID-65419
Xen XSM/Flask Hypercalls Local Integer Overflow Vulnerability

Source: CONFIRM
Type: Patch, Vendor Advisory
http://xenbits.xen.org/xsa/advisory-84.html

Source: XF
Type: UNKNOWN
xen-cve20141894-dos(91312)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xen:xen:3.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.0.3:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.0.4:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.1.3:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.1.4:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.2.0:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/o:xen:xen:*:*:*:*:*:*:*:* (Version <= 3.2.3)

  • Configuration CCN 1:
  • cpe:/a:xensource:xen:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20141894
    V
    CVE-2014-1894
    2022-05-20
    oval:org.opensuse.security:def:33793
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:30284
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:29458
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:34006
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:55977
    P
    Security update for xen (Moderate)
    2021-11-29
    oval:org.opensuse.security:def:34595
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:56089
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:57520
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:33029
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:33730
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:31687
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:34538
    P
    Security update for postgresql12 (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:33706
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:33962
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:56051
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:55220
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:33938
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:32950
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:30210
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:32938
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:33667
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:32939
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:34452
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:29372
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30199
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:34440
    P
    Security update for curl (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:57446
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:30198
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:33899
    P
    Security update for permissions (Important)
    2021-04-29
    oval:org.opensuse.security:def:34412
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:33636
    P
    Security update for xen (Important)
    2021-04-19
    oval:org.opensuse.security:def:55885
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:34644
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:33774
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:28940
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:28928
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:28929
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:31649
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:29368
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:29957
    P
    Security update for openssl (Important)
    2020-12-11
    oval:org.opensuse.security:def:55777
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:33618
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35698
    P
    foomatic-filters-3.0.2-269.35.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35739
    P
    libapr1-1.3.3-11.18.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:28857
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:33171
    P
    libpixman-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34844
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:30967
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26461
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:55047
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27985
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:30400
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:33261
    P
    strongswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29600
    P
    Security update for augeas (Low)
    2020-12-01
    oval:org.opensuse.security:def:34951
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:26536
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55326
    P
    m4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28087
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33491
    P
    Security update for libtiff
    2020-12-01
    oval:org.opensuse.security:def:29807
    P
    Security update for jakarta-commons-collections (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35016
    P
    Security update for graphviz (Low)
    2020-12-01
    oval:org.opensuse.security:def:26745
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28140
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29140
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29895
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26886
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28822
    P
    Security update for python-lxml
    2020-12-01
    oval:org.opensuse.security:def:29283
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:33850
    P
    Security update for icu
    2020-12-01
    oval:org.opensuse.security:def:34209
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30505
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27090
    P
    bash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27408
    P
    ghostscript-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33164
    P
    libmysqlclient15-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29521
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:30632
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:29160
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34304
    P
    Security update for quagga (Low)
    2020-12-01
    oval:org.opensuse.security:def:30649
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:27178
    P
    libcgroup1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27483
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33316
    P
    openvpn-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29624
    P
    Security update for Mono
    2020-12-01
    oval:org.opensuse.security:def:29172
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:30859
    P
    Security update for e2fsprogs
    2020-12-01
    oval:org.opensuse.security:def:27236
    P
    lxc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54647
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27693
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:33561
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29681
    P
    Security update for ecryptfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34684
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:33170
    P
    libotr2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34685
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:30947
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:27909
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:26460
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:54809
    P
    icu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27834
    P
    Security update for mono-core (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30363
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33182
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29515
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34902
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31011
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26472
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:28038
    P
    Security update for cracklib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33396
    P
    Security update for SUSE Manager Client Tools (Critical)
    2020-12-01
    oval:org.opensuse.security:def:29753
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34990
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:26664
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55492
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28126
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29009
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33548
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:29856
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:35060
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26802
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28184
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29226
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29913
    P
    Security update for libcap
    2020-12-01
    oval:org.opensuse.security:def:34208
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:30416
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:27037
    P
    syslog-ng on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27407
    P
    gdk-pixbuf on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30595
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34220
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30562
    P
    Security update for pcp
    2020-12-01
    oval:org.opensuse.security:def:27139
    P
    gpgme on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56170
    P
    Security update for dbus-1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27419
    P
    imlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33259
    P
    squidGuard on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29575
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29161
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30804
    P
    Security update for cifs-utils (Important)
    2020-12-01
    oval:org.opensuse.security:def:27192
    P
    libksba on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54646
    P
    patch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27611
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:33404
    P
    Security update for zeromq (Important)
    2020-12-01
    oval:org.opensuse.security:def:29663
    P
    Security update for cvs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29241
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27874
    P
    Security update for rubygem-activerecord-2_3 and rubygem-activesupport-2_3
    2020-12-01
    oval:org.opensuse.security:def:54669
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27750
    P
    Security update for gd
    2020-12-01
    oval:org.opensuse.security:def:29725
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.mitre.oval:def:25115
    P
    SUSE-SU-2014:0446-1 -- Security update for Xen
    2014-09-08
    oval:org.mitre.oval:def:25302
    P
    SUSE-SU-2014:0372-1 -- Security update for Xen
    2014-09-08
    oval:org.mitre.oval:def:25390
    P
    SUSE-SU-2014:0373-1 -- Security update for Xen
    2014-09-08
    oval:com.ubuntu.precise:def:20141894000
    V
    CVE-2014-1894 on Ubuntu 12.04 LTS (precise) - medium.
    2014-04-01
    oval:org.opensuse.security:def:80154
    P
    Security update for Xen
    2014-02-27
    BACK
    xen xen 3.0.2
    xen xen 3.0.3
    xen xen 3.0.4
    xen xen 3.1.3
    xen xen 3.1.4
    xen xen 3.2.0
    xen xen 3.2.1
    xen xen 3.2.2
    xen xen *
    xensource xen 4.0