PT-2012-4139 · Xen+2 · Xen+2
Publicado
2012-07-31
·
Atualizado
2024-06-15
·
CVE-2012-2625
CVSS v2.0
2.7
Baixa
| Vetor | AV:A/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Xen unstable before changeset 25589:60f09d1ab1fe
Xen versions 4.2.x
Xen versions 4.1.x
Description
The issue allows local para-virtualized guest users to cause a denial of service, specifically memory consumption, by utilizing a large compressed kernel image. This can be achieved through either bzip2 or lzma compression.
Recommendations
For Xen unstable before changeset 25589:60f09d1ab1fe, update to a version after changeset 25589:60f09d1ab1fe to resolve the issue.
For Xen versions 4.2.x, consider updating to a newer version that includes the fix for this issue.
For Xen versions 4.1.x, consider updating to a newer version that includes the fix for this issue.
As a temporary workaround, consider restricting the size of compressed kernel images to prevent excessive memory consumption.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Suse
Xen