PT-2012-4780 · Citrix+1 · Xen+2
Published
2012-11-23
·
Updated
2013-02-01
·
CVE-2012-3516
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.2
Citrix XenServer version 6.0.2
Description
The issue allows local guest kernels or administrators to cause a denial of service, potentially leading to a host crash, and possibly gain privileges. This is achieved by crafting a grant reference that triggers a write to an arbitrary hypervisor memory location through the GNTTABOP swap grant ref sub-operation in the grant table hypercall.
Recommendations
For Xen version 4.2, update to a version that includes a fix for this issue.
For Citrix XenServer version 6.0.2, apply the recommended patch or update to a newer version that addresses this problem.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen
Xenserver