ALPINE-CVE-2018-10472 PUBLISHED CVSS 5.599999904632568 MEDIUM

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Risk Scores

CVSS v3.0
5.599999904632568
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Alpine:v3.17xen4.0.1-r0, 4.9.1-r3, 4.9.1-r2
Alpine:v3.6xen0, 4.8.3-r0, 4.8.2-r6
Alpine:v3.19xen4.6.0-r4, 4.6.0-r5, 4.6.1-r0
Alpine:v3.9xen4.1.2-r5, 4.9.1-r3, 4.9.1-r2
Alpine:v3.22xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.23xen4.3.1-r2, 4.9.1-r3, 4.9.1-r2
Alpine:v3.21xen4.9.1-r3, 0, 4.0.1-r1
Alpine:v3.16xen4.0.1-r1, 4.9.1-r3, 4.9.1-r2
Alpine:v3.8xen4.0.1-r0, 4.9.1-r3, 4.9.1-r2
Alpine:v3.18xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.7xen4.3.2-r3, 0, 4.0.1-r0
Alpine:v3.15xen4.2.1-r6, 4.2.1-r5, 4.2.1-r3
Alpine:v3.20xen4.9.1-r0, 4.6.3-r1, 4.5.0-r1
Alpine:v3.13xen4.2.1-r6, 4.0.1-r0, 4.0.1-r2
Alpine:v3.11xen4.4.1-r7, 4.9.1-r3, 4.9.1-r2
Alpine:v3.14xen4.2.0-r6, 4.2.0-r5, 4.2.0-r3
Alpine:v3.4xen4.5.0-r1, 4.6.6-r4, 4.6.6-r3
Alpine:v3.5xen4.0.1-r3, 4.1.0-r0, 4.1.0-r2
Alpine:v3.10xen4.6.3-r0, 4.9.1-r1, 4.9.1-r0
Alpine:v3.12xen0, 4.9.0-r0, 4.7.1-r1

Timeline

References

Open in Interactive Console →