PT-2007-7272 · Xen+1 · Xen+1
Publicado
2007-12-17
·
Atualizado
2017-09-29
·
CVE-2007-6416
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.1.2 and earlier
Description
The issue concerns the copy to user function in the PAL emulation functionality for Xen, specifically when running on ia64 systems. It allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.
Recommendations
For Xen versions 3.1.2 and earlier, consider updating to a newer version to mitigate the risk, as the copy to user function in the PAL emulation functionality poses a security risk when running on ia64 systems.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Xen