CVE-2015-2152
published 2015-03-18CVE-2015-2152: Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which…
PriorityP49low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.42%
34.0th percentile
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-9 (bookworm) | xen 4.4.1-9 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | <= 4.5.0 | — |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4h5r-jgg6-766g: Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-2152 [LOW] GHSA-4h5r-jgg6-766g: Xen 4
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
OSV
CVE-2015-2152: Xen 4
osv·2015-03-18·CVSS 1.9
CVE-2015-2152 [LOW] CVE-2015-2152: Xen 4
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
Red Hat
xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
vendor_redhat·2015-03-12·CVSS 1.9
CVE-2015-2152 [LOW] xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
Statement: Not vulnerable. This issue did not affect the versions of xen as shipped with Red Hat Enterprise Linux 5 as they did not include affected libxc library.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-2152: xen - Xen 4.5.x and earlier enables certain default backends when emulating a VGA devi...
vendor_debian·2015·CVSS 1.9
CVE-2015-2152 [LOW] CVE-2015-2152: xen - Xen 4.5.x and earlier enables certain default backends when emulating a VGA devi...
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.
Scope: local
bookworm: resolved (fixed in 4.4.1-9)
bullseye: resolved (fixed in 4.4.1-9)
forky: resolved (fixed in 4.4.1-9)
sid: resolved (fixed in 4.4.1-9)
trixie: resolved (fixed in 4.4.1-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119) [fedora-all]
bugzilla·2015-03-12·CVSS 1.9
CVE-2015-2152 [LOW] CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119) [fedora-all]
CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
bugzilla·2015-03-11·CVSS 1.9
CVE-2015-2152 [LOW] CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
ISSUE DESCRIPTION
When instantiating an emulated VGA device for an x86 HVM guest qemu
will by default enable a backend to expose that device, either SDL or
VNC depending on the version of qemu and the build time configuration.
The libxl toolstack library does not explicitly disable these default
backends when they are not enabled, leading to an unexpected backend
running.
If either SDL or VNC is explicitly enabled in the guest configuration
then only the expected backends will be enabled.
This affects qemu-xen and qemu-xen-traditional differently.
If qemu-xen was compiled with SDL support then this would result in an
SDL window being opened if $DISPLAY is valid, or a failure to start
the guest
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://www.securityfocus.com/bid/73068http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031919http://xenbits.xen.org/xsa/advisory-119.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://www.securityfocus.com/bid/73068http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031919http://xenbits.xen.org/xsa/advisory-119.htmlhttps://security.gentoo.org/glsa/201504-04
2015-03-18
Published