Lucene search

K
cve[email protected]CVE-2014-1896
HistoryApr 01, 2014 - 6:35 a.m.

CVE-2014-1896

2014-04-0106:35:53
CWE-20
web.nvd.nist.gov
26
cve-2014-1896
xen
libvchan
denial of service
privilege escalation

4.9 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%

The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a “read or write past the end of the ring.”

Affected configurations

NVD
Node
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2
OR
xenxenMatch4.2.3
OR
xenxenMatch4.3.0
OR
xenxenMatch4.3.1
OR
xenxenMatch4.4.0rc1

4.9 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%