Lucene search

K
cve[email protected]CVE-2012-3498
HistoryNov 23, 2012 - 8:55 p.m.

CVE-2012-3498

2012-11-2320:55:03
CWE-20
web.nvd.nist.gov
39
xen 4.1
xen 4.2
citrix xenserver 6.0.2
physdevop_map_pirq
vulnerability
denial of service
host crash
memory read
nvd
cve-2012-3498

5.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:P/I:N/A:C

5.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%

PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.

Affected configurations

NVD
Node
citrixxenserverRange6.0.2
OR
xenxenMatch4.1.0
OR
xenxenMatch4.2.0

References

5.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:P/I:N/A:C

5.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.1%