Lucene search

K
cve[email protected]CVE-2012-5514
HistoryDec 13, 2012 - 11:53 a.m.

CVE-2012-5514

2012-12-1311:53:49
web.nvd.nist.gov
37
xen
4.2
guest_physmap_mark
denial of service
cve-2012-5514
security vulnerability

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

3.6 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

Affected configurations

NVD
Node
xenxenRange4.2.0
OR
xenxenMatch3.0.2
OR
xenxenMatch3.0.3
OR
xenxenMatch3.0.4
OR
xenxenMatch3.1.3
OR
xenxenMatch3.1.4
OR
xenxenMatch3.2.0
OR
xenxenMatch3.2.1
OR
xenxenMatch3.2.2
OR
xenxenMatch3.2.3
OR
xenxenMatch3.3.0
OR
xenxenMatch3.3.1
OR
xenxenMatch3.3.2
OR
xenxenMatch3.4.0
OR
xenxenMatch3.4.1
OR
xenxenMatch3.4.2
OR
xenxenMatch3.4.3
OR
xenxenMatch3.4.4
OR
xenxenMatch4.0.0
OR
xenxenMatch4.0.1
OR
xenxenMatch4.0.2
OR
xenxenMatch4.0.3
OR
xenxenMatch4.0.4
OR
xenxenMatch4.1.0
OR
xenxenMatch4.1.1
OR
xenxenMatch4.1.2
OR
xenxenMatch4.1.3

References

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

3.6 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%