Security issue

This is used for general discussion that is not necessarily server-related.
Post Reply
User avatar
TacTicToe
This is my homepage
This is my homepage
Posts: 848
https://www.youtube.com/channel/UC40BgXanDqOYoVCYFDSTfHA
Joined: Fri Feb 18, 2011 1:08 pm
Location: USA
Contact:

Security issue

Post by TacTicToe »

So apparently all my servers are about to get a reboot due to a security issue. Any chance we can know what this security issue is? Even if we are told after the reboots?
User avatar
Edge100x
Founder
Founder
Posts: 13131
Joined: Thu Apr 18, 2002 11:04 pm
Location: Seattle
Contact:

Re: Security issue

Post by Edge100x »

We can't be more specific right now, but we can explain in more depth next month.
User avatar
rymax99
This is my homepage
This is my homepage
Posts: 143
Joined: Sun Feb 02, 2014 2:08 pm
Location: Florida
Contact:

Re: Security issue

Post by rymax99 »

With a little bit of research, you could probably find out. :wink:
User avatar
Edge100x
Founder
Founder
Posts: 13131
Joined: Thu Apr 18, 2002 11:04 pm
Location: Seattle
Contact:

Re: Security issue

Post by Edge100x »

It was XSA-108, which was embargoed. Following certain steps could result in a local attacker being able to crash the machine hosting a VDS or to read data from the hypervisor or other customers:

http://xenbits.xen.org/xsa/advisory-108.html

This is not a terribly serious vulnerability compared to others that Xen has seen over the years (some of them specific to PV guests, which we do not use). We needed to act partially because it has been getting so much exposure through the media, which increases the likelihood of an attacker developing tools for it.
User avatar
TacTicToe
This is my homepage
This is my homepage
Posts: 848
Joined: Fri Feb 18, 2011 1:08 pm
Location: USA
Contact:

Re: Security issue

Post by TacTicToe »

Well I guess technically today is next month, so thank you for the explanation. I was getting some complaints about the lag on our Homefront server in New York. People really are not USED to lag on our servers, so when it was happening, my steam chat kind of blew up. So with the hardware upgrades and security stuff, I'm just glad it is all over and things are back to normal.

Glad everything has been resolved.

Thanks John! 8)
Post Reply