PT-2007-7272 · Xen+1 · Xen+1

Publicado

2007-12-17

·

Atualizado

2017-09-29

·

CVE-2007-6416

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 3.1.2 and earlier
Description The issue concerns the copy to user function in the PAL emulation functionality for Xen, specifically when running on ia64 systems. It allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.
Recommendations For Xen versions 3.1.2 and earlier, consider updating to a newer version to mitigate the risk, as the copy to user function in the PAL emulation functionality poses a security risk when running on ia64 systems.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6416
RHSA-2008:0089
RHSA-2008_0089

Produtos afetados

Red Hat
Xen