PT-2008-6768 · Citrix · Xen
Publicado
2008-12-24
·
Atualizado
2017-08-08
·
CVE-2008-5716
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xen version 3.3.0
Description
The issue allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to certain files. This can be done by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid within the /local/domain xenstore directory tree.
Recommendations
For Xen version 3.3.0, consider restricting write access to the /local/domain xenstore directory tree to prevent guest OS users from causing a denial of service. As a temporary workaround, restrict access to the console/tty, console/limit, and image/device-model-pid files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Xen