CVE-2013-4369
EPSS 0.06%
Description
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
How to fix CVE-2013-4369
To remediate CVE-2013-4369, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.4.0-1 or later
Is CVE-2013-4369 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.0-1