PT-2014-4351 · Xen+1 · Xen+1

Publicado

2014-04-01

·

Atualizado

2017-01-07

·

CVE-2014-1896

CVSS v2.0

4.9

Média

VetorAV:A/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 4.2.x through 4.4-RC
Description The issue is related to the do send and do recv functions in io.c in libvchan, which allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes. This triggers a "read or write past the end of the ring."
Recommendations For Xen versions 4.2.x through 4.4-RC, consider restricting access to the vulnerable do send and do recv functions in io.c in libvchan as a temporary workaround until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1896

Produtos afetados

Suse
Xen