WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] are Xen 3.1.0 kernels CVE-2007-4573 vulnerable

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] are Xen 3.1.0 kernels CVE-2007-4573 vulnerable
From: "S.Çağlar Onur" <caglar@xxxxxxxxxxxxx>
Date: Tue, 2 Oct 2007 23:52:09 +0300
Delivery-date: Tue, 02 Oct 2007 13:55:38 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <Pine.LNX.4.64.0710011215020.7452@xxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Organization: TÜBİTAK / UEKAE
References: <Pine.LNX.4.64.0710011215020.7452@xxxxxxxxxxxxxxxxx>
Reply-to: caglar@xxxxxxxxxxxxx
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.6 (enterprise 0.20070907.709405)
Hi;

01 Eki 2007 Pts tarihinde, Steven Timm şunları yazmıştı: 
> Does anyone know if the Xen 3.1.0 kernels as distributed in
> the "open source" tarballs (x86_64 version) are vulnerable to the
> recently-announced  vulnerability CVE-2007-4573?
> IF so, is there any plan to release patched tarballs  anytime soon?

Yes it is. And current provided tarball also vulnerable against ~30 CVE+ 
(cause all these vulnerabilities are discovered after 2.6.18 which is Xen-3.x 
based on) so i suggest using your distros provided one instead of upstream 
one.

Cheers
-- 
S.Çağlar Onur <caglar@xxxxxxxxxxxxx>
http://cekirdek.pardus.org.tr/~caglar/

Linux is like living in a teepee. No Windows, no Gates and an Apache in house!

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users