PT-2017-2782 · Xen+1 · Xen+1

Publicado

2017-08-02

·

Atualizado

2024-06-15

·

CVE-2017-12137

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to insufficient access control in the mm.c component of the Xen hypervisor, allowing local PV guest OS users to gain host OS privileges. This can be achieved through vectors related to map grant ref.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02041
CVE-2017-12137
DLA-1132-1
DSA-3969-1
OPENSUSE-SU-2017_2394-1
OPENSUSE-SU-2017_2398-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2017:2319-1
SUSE-SU-2017:2326-1
SUSE-SU-2017:2327-1
SUSE-SU-2017:2327-2
SUSE-SU-2017:2339-1
SUSE-SU-2017:2450-1
SUSE-SU-2017:2541-1

Produtos afetados

Suse
Xen