Lucene search

K
cve[email protected]CVE-2012-3494
HistoryNov 23, 2012 - 8:55 p.m.

CVE-2012-3494

2012-11-2320:55:03
CWE-264
web.nvd.nist.gov
39
xen
citrix xenserver
cve-2012-3494
vulnerability
os guest users
denial of service
dr7 debug control register
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%

The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.

Affected configurations

NVD
Node
citrixxenserverRange6.0.2-x64
OR
citrixxenserverRange6.0.2-x86
OR
xenxenMatch4.0.0-x64
OR
xenxenMatch4.0.0-x86
OR
xenxenMatch4.1.0-x64
OR
xenxenMatch4.1.0-x86
OR
xenxenMatch4.2.0-x64
OR
xenxenMatch4.2.0-x86

References

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%