Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44531
HistoryNov 30, 2023 - 8:56 p.m.

Buffer Overflow

2023-11-3020:56:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
xen
software
vulnerability
libfsimage
buffer overflow
stack buffer
application crash

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

xen is vulnerable to Buffer Overflow. The vulnerability exists because the libfsimage is utilized by pygrub to inspect guest disks, creating a potential avenue for an attacker to induce a stack buffer overflow in libfsimage, ultimately resulting in an application crash.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%