CVE-2012-4544

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html
http://osvdb.org/86619
http://rhn.redhat.com/errata/RHSA-2013-0241.html
http://secunia.com/advisories/51071 Vendor Advisory
http://secunia.com/advisories/51324
http://secunia.com/advisories/51352
http://secunia.com/advisories/51413
http://www.debian.org/security/2013/dsa-2636
http://www.openwall.com/lists/oss-security/2012/10/26/3
http://www.securityfocus.com/bid/56289
http://www.securitytracker.com/id?1027699
https://exchange.xforce.ibmcloud.com/vulnerabilities/79617
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html
http://osvdb.org/86619
http://rhn.redhat.com/errata/RHSA-2013-0241.html
http://secunia.com/advisories/51071 Vendor Advisory
http://secunia.com/advisories/51324
http://secunia.com/advisories/51352
http://secunia.com/advisories/51413
http://www.debian.org/security/2013/dsa-2636
http://www.openwall.com/lists/oss-security/2012/10/26/3
http://www.securityfocus.com/bid/56289
http://www.securitytracker.com/id?1027699
https://exchange.xforce.ibmcloud.com/vulnerabilities/79617
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
cpe:2.3:o:xen:xen:4.1.0:*:*:*:*:*:*:*
cpe:2.3:o:xen:xen:4.1.1:*:*:*:*:*:*:*
cpe:2.3:o:xen:xen:4.1.2:*:*:*:*:*:*:*
cpe:2.3:o:xen:xen:4.1.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:43

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html - () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html - () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html - () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html - () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html - () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html -
References () http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html -
References () http://osvdb.org/86619 - () http://osvdb.org/86619 -
References () http://rhn.redhat.com/errata/RHSA-2013-0241.html - () http://rhn.redhat.com/errata/RHSA-2013-0241.html -
References () http://secunia.com/advisories/51071 - Vendor Advisory () http://secunia.com/advisories/51071 - Vendor Advisory
References () http://secunia.com/advisories/51324 - () http://secunia.com/advisories/51324 -
References () http://secunia.com/advisories/51352 - () http://secunia.com/advisories/51352 -
References () http://secunia.com/advisories/51413 - () http://secunia.com/advisories/51413 -
References () http://www.debian.org/security/2013/dsa-2636 - () http://www.debian.org/security/2013/dsa-2636 -
References () http://www.openwall.com/lists/oss-security/2012/10/26/3 - () http://www.openwall.com/lists/oss-security/2012/10/26/3 -
References () http://www.securityfocus.com/bid/56289 - () http://www.securityfocus.com/bid/56289 -
References () http://www.securitytracker.com/id?1027699 - () http://www.securitytracker.com/id?1027699 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/79617 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/79617 -

Information

Published : 2012-10-31 16:55

Updated : 2024-11-21 01:43


NVD link : CVE-2012-4544

Mitre link : CVE-2012-4544

CVE.ORG link : CVE-2012-4544


JSON object : View

Products Affected

xen

  • xen
CWE
CWE-20

Improper Input Validation