PT-2012-6227 · Xen · Xen
Publicado
2012-11-23
·
Atualizado
2017-08-29
·
CVE-2012-6036
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.0 through 4.2
Description
The issue concerns the Transcendent Memory (TMEM) in Xen, where certain functions do not check for negative id pools. This allows local guest OS users to cause a denial of service, resulting in memory corruption and host crash, or possibly execute arbitrary code.
Recommendations
For Xen versions 4.0 through 4.2, consider disabling the
memc save get next page, tmemc restore put page, and tmemc restore flush page functions as a temporary workaround until a patch is available. Restrict access to the TMEM component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Xen