PT-2012-6004 · Xen · Xen

Publicado

2012-12-13

·

Atualizado

2024-06-15

·

CVE-2012-5525

CVSS v2.0

4.7

Média

VetorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen version 4.2
Description The issue allows local PV guest OS administrators to cause a denial of service (crash) by exploiting the get page from gfn hypercall function. This is achieved via a crafted GFN that triggers a buffer over-read.
Recommendations For Xen version 4.2, consider disabling the get page from gfn hypercall function as a temporary workaround until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-5525
OPENSUSE-SU-2024:10196-1

Produtos afetados

Xen