Lucene search

K
cve[email protected]CVE-2013-0154
HistoryJan 12, 2013 - 4:33 a.m.

CVE-2013-0154

2013-01-1204:33:49
web.nvd.nist.gov
31
cve-2013-0154
xen
denial of service
assertion failure
hypervisor crash
hypercall
security vulnerability.

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%

The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.

Affected configurations

NVD
Node
xenxenMatch4.2.0
CPENameOperatorVersion
xen:xenxeneq4.2.0

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%