PT-2014-5102 · Xen+1 · Xen+1
Chen Baozi
+1
·
Publicado
2014-05-02
·
Atualizado
2018-10-30
·
CVE-2014-3125
CVSS v2.0
6.2
Média
| Vetor | AV:A/AC:L/Au:S/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.4.x
Description
The issue is related to the improper context switching of the CNTKCTL EL1 register when Xen is running on an ARM system. This allows local guest users to modify the hardware timers, which can cause a denial of service (crash) via unspecified vectors.
Recommendations
For Xen version 4.4.x, consider applying a patch or fix that properly handles the context switching of the CNTKCTL EL1 register to prevent local guest users from modifying the hardware timers and causing a denial of service.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Xen