UBUNTU-CVE-2014-3969

Source
https://ubuntu.com/security/CVE-2014-3969
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-3969.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-3969
Upstream
  • CVE-2014-3969
Published
2014-06-05T20:55:00Z
Modified
2026-04-22T09:43:38.076213Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to gain privileges via unspecified vectors.

References

Affected packages

Ubuntu:14.04:LTS / xen

Package

Name
xen
Purl
pkg:deb/ubuntu/xen@4.4.0-0ubuntu5.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-0ubuntu5.1

Affected versions

4.*
4.3.0-1ubuntu1
4.3.0-1ubuntu2
4.3.0-1ubuntu3
4.3.0-1ubuntu4
4.3.0-1ubuntu5
4.4.0-0ubuntu3
4.4.0-0ubuntu4
4.4.0-0ubuntu5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "libxen-4.4"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "libxen-ocaml"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "libxenstore3.0"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.1-amd64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.3-amd64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.3-armhf"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.4-amd64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.4-arm64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-hypervisor-4.4-armhf"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-system-amd64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-system-arm64"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-system-armhf"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-utils-4.4"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xen-utils-common"
        },
        {
            "binary_version": "4.4.0-0ubuntu5.1",
            "binary_name": "xenstore-utils"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-3969.json"