OracleVM 3.1 : xen (OVMSA-2012-0021)

High Nessus Plugin ID 79477


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- x86-64: detect processors subject to AMD erratum #121 and refuse to boot(CVE-2006-0744)

- guest denial of service on syscall/sysenter exception generation (CVE-2012-0217),(CVE-2012-0218)

- Remove unnecessary balloon retries on vm create. This is a backport from fix for bug 14143327.


Update the affected xen / xen-devel / xen-tools packages.

See Also

Plugin Details

Severity: High

ID: 79477

File Name: oraclevm_OVMSA-2012-0021.nasl

Version: $Revision: 1.6 $

Type: local

Published: 2014/11/26

Modified: 2018/02/01

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:xen, p-cpe:/a:oracle:vm:xen-devel, p-cpe:/a:oracle:vm:xen-tools, cpe:/o:oracle:vm_server:3.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2012/06/13

Exploitable With


Core Impact

Reference Information

CVE: CVE-2006-0744, CVE-2012-0217, CVE-2012-0218

BID: 53856, 53955

OSVDB: 82850, 83072

CWE: 20