CentOS 5 : xen (CESA-2016:2963)
Low Nessus Plugin ID 95953
SynopsisThe remote CentOS host is missing one or more security updates.
DescriptionAn update for xen is now available for Red Hat Enterprise Linux 5.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Xen is a virtual machine monitor
Security Fix(es) :
* An out of bounds array access issue was found in the Xen virtual machine monitor, built with the QEMU ioport support. It could occur while doing ioport read/write operations, if guest was to supply a 32bit address parameter. A privileged guest user/process could use this flaw to potentially escalate their privileges on a host.
Red Hat would like to thank the Xen project for reporting this issue.
SolutionUpdate the affected xen packages.