CVE-2015-2152
EPSS 0.08%
描述
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
如何修補 CVE-2015-2152
要修補 CVE-2015-2152,請將受影響套件升級到下列已修補版本。
- Debian/xen—升級至 4.4.1-9 或更新版本
CVE-2015-2152 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4.4.1-9