Lucene search

K
cve[email protected]CVE-2012-6034
HistoryNov 23, 2012 - 8:55 p.m.

CVE-2012-6034

2012-11-2320:55:04
CWE-20
web.nvd.nist.gov
28
cve-2012-6034
xen 4.0
xen 4.1
xen 4.2
transcendent memory
tmem
memory corruption
host crash
arbitrary code
denial of service

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.0%

The (1) tmemc_save_get_next_page and (2) tmemc_save_get_next_inv functions and the (3) TMEMC_SAVE_GET_POOL_UUID sub-operation in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 “do not check incoming guest output buffer pointers,” which allows local guest OS users to cause a denial of service (memory corruption and host crash) or execute arbitrary code via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.

Affected configurations

NVD
Node
xenxenMatch4.0.0
OR
xenxenMatch4.1.0
OR
xenxenMatch4.2.0

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.0%