Citrix XenServer Multiple Vulnerabilities (CTX220771)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote host is affected by multiple vulnerabilities.

Description :

The version of Citrix XenServer running on the remote host is missing
a security hotfix. It is, therefore, affected by the following
vulnerabilities :

- A flaw exists in the blit_region_is_unsafe() function
within file hw/display/cirrus_vga.c when handling a
backward mode bitblt copy. A guest attacker with
administrative privileges can exploit this to crash the
QEMU process or potentially execute arbitrary code with
elevated privileges. (CVE-2017-2615)

- A flaw exists in the cirrus_bitblt_cputovideo() function
within file hw/display/cirrus_vga.c when running in
CIRRUS_BLTMODE_MEMSYSSRC mode due to improper memory
region checks. A guest attacker with administrative
privileges can exploit this to crash the QEMU process or
potentially execute arbitrary code with elevated
privileges. (CVE-2017-2620)

See also :

https://support.citrix.com/article/CTX220771

Solution :

Apply the appropriate hotfix according to the vendor advisory.

Risk factor :

High / CVSS Base Score : 7.4
(CVSS2#AV:A/AC:M/Au:S/C:C/I:C/A:C)
CVSS Temporal Score : 6.7
(CVSS2#E:POC/RL:U/RC:ND)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 97525 ()

Bugtraq ID: 95990
96378

CVE ID: CVE-2017-2615
CVE-2017-2620

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now