Lucene search

K
cveRedhatCVE-2011-1583
HistoryAug 12, 2011 - 6:55 p.m.

CVE-2011-1583

2011-08-1218:55:00
CWE-189
redhat
web.nvd.nist.gov
43
xen
integer overflows
xc_dom_bzimageloader.c
local users
denial of service
execute arbitrary code
vulnerability
cve-2011-1583
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.2%

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

Affected configurations

Nvd
Node
citrixxenMatch3.2.0
OR
citrixxenMatch3.3.0
OR
citrixxenMatch4.0.0
OR
citrixxenMatch4.1.0
VendorProductVersionCPE
citrixxen3.2.0cpe:2.3:a:citrix:xen:3.2.0:*:*:*:*:*:*:*
citrixxen3.3.0cpe:2.3:a:citrix:xen:3.3.0:*:*:*:*:*:*:*
citrixxen4.0.0cpe:2.3:a:citrix:xen:4.0.0:*:*:*:*:*:*:*
citrixxen4.1.0cpe:2.3:a:citrix:xen:4.1.0:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.2%