The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html - | |
References | () http://osvdb.org/86619 - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0241.html - | |
References | () http://secunia.com/advisories/51071 - Vendor Advisory | |
References | () http://secunia.com/advisories/51324 - | |
References | () http://secunia.com/advisories/51352 - | |
References | () http://secunia.com/advisories/51413 - | |
References | () http://www.debian.org/security/2013/dsa-2636 - | |
References | () http://www.openwall.com/lists/oss-security/2012/10/26/3 - | |
References | () http://www.securityfocus.com/bid/56289 - | |
References | () http://www.securitytracker.com/id?1027699 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/79617 - |
Information
Published : 2012-10-31 16:55
Updated : 2024-11-21 01:43
NVD link : CVE-2012-4544
Mitre link : CVE-2012-4544
CVE.ORG link : CVE-2012-4544
JSON object : View
Products Affected
xen
- xen
CWE
CWE-20
Improper Input Validation