Lucene search

K
cve[email protected]CVE-2012-3496
HistoryNov 23, 2012 - 8:55 p.m.

CVE-2012-3496

2012-11-2320:55:03
CWE-16
web.nvd.nist.gov
37
cve-2012-3496
xenmem_populate_physmap
denial of service
bug
host crash

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%

XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.

Affected configurations

NVD
Node
citrixxenserverRange6.0.2
OR
xenxenMatch4.0.0
OR
xenxenMatch4.1.0
OR
xenxenMatch4.2.0

References

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%