Candidate: CVE-2013-1964 PublicDate: 2013-05-21 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1964 http://lists.xen.org/archives/html/xen-announce/2013-04/msg00006.html Description: Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors. Ubuntu-Description: Notes: mdeslaur> hypervisor packages are in universe. For mdeslaur> issues in the hypervisor, add appropriate mdeslaur> tags to each section, ex: mdeslaur> Tags_xen: universe-binary mdeslaur> This is XSA-50 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_xen-3.1: upstream_xen-3.1: not-affected hardy_xen-3.1: ignored (reached end-of-life) lucid_xen-3.1: DNE oneiric_xen-3.1: DNE precise_xen-3.1: DNE quantal_xen-3.1: DNE raring_xen-3.1: DNE devel_xen-3.1: DNE Patches_xen-3.2: upstream_xen-3.2: not-affected hardy_xen-3.2: ignored (reached end-of-life) lucid_xen-3.2: DNE oneiric_xen-3.2: DNE precise_xen-3.2: DNE quantal_xen-3.2: DNE raring_xen-3.2: DNE devel_xen-3.2: DNE Patches_xen-3.3: upstream_xen-3.3: not-affected hardy_xen-3.3: DNE lucid_xen-3.3: not-affected oneiric_xen-3.3: DNE precise_xen-3.3: DNE quantal_xen-3.3: DNE raring_xen-3.3: DNE devel_xen-3.3: DNE Tags_xen: universe-binary Patches_xen: upstream: http://lists.xen.org/archives/html/xen-announce/2013-04/bin2M8DLOFIr7.bin (4.1) upstream_xen: needed hardy_xen: DNE lucid_xen: DNE oneiric_xen: ignored (reached end-of-life) precise_xen: released (4.1.2-2ubuntu2.9) quantal_xen: released (4.1.3-3ubuntu1.6) raring_xen: not-affected (4.2.1-0ubuntu3) devel_xen: not-affected (4.2.1-0ubuntu3)