Lucene search

K
freebsdFreeBSDF1DEED23-27EC-11E5-A4A5-002590263BF5
HistoryJul 07, 2015 - 12:00 a.m.

xen-tools -- xl command line config handling stack overflow

2015-07-0700:00:00
vuxml.freebsd.org
10

6.8 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

30.2%

The Xen Project reports:

The xl command line utility mishandles long configuration values
when passed as command line arguments, with a buffer overrun.
A semi-trusted guest administrator or controller, who is intended
to be able to partially control the configuration settings for a
domain, can escalate their privileges to that of the whole host.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchxen-tools= 4.1UNKNOWN
FreeBSDanynoarchxen-tools< 4.5.0_8UNKNOWN

6.8 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

30.2%