Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-5525
HistoryDec 13, 2012 - 11:53 a.m.

CVE-2012-5525

2012-12-1311:53:49
Debian Security Bug Tracker
security-tracker.debian.org
13

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

0.002 Low

EPSS

Percentile

55.1%

The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

OSVersionArchitecturePackageVersionFilename
Debian12allxen< 4.17.3+10-g091466ba55-1~deb12u1xen_4.17.3+10-g091466ba55-1~deb12u1_all.deb
Debian11allxen< 4.14.6-1xen_4.14.6-1_all.deb
Debian999allxen< 4.17.3+36-g54dacb5c02-1xen_4.17.3+36-g54dacb5c02-1_all.deb
Debian13allxen< 4.17.3+36-g54dacb5c02-1xen_4.17.3+36-g54dacb5c02-1_all.deb

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

0.002 Low

EPSS

Percentile

55.1%