Lucene search

K
cve[email protected]CVE-2012-4544
HistoryOct 31, 2012 - 4:55 p.m.

CVE-2012-4544

2012-10-3116:55:05
CWE-20
web.nvd.nist.gov
38
cve-2012-4544
xen
pv domain builder
denial of service
local guest administrators
memory consumption

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.8 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Affected configurations

NVD
Node
xenxenRange4.2.0
OR
xenxenMatch4.1.0
OR
xenxenMatch4.1.1
OR
xenxenMatch4.1.2
OR
xenxenMatch4.1.3

References

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.8 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%