T
he PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.html - | |
| References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.html - | |
| References | () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html - | |
| References | () http://osvdb.org/86619 - | |
| References | () http://rhn.redhat.com/errata/RHSA-2013-0241.html - | |
| References | () http://secunia.com/advisories/51071 - Vendor Advisory | |
| References | () http://secunia.com/advisories/51324 - | |
| References | () http://secunia.com/advisories/51352 - | |
| References | () http://secunia.com/advisories/51413 - | |
| References | () http://www.debian.org/security/2013/dsa-2636 - | |
| References | () http://www.openwall.com/lists/oss-security/2012/10/26/3 - | |
| References | () http://www.securityfocus.com/bid/56289 - | |
| References | () http://www.securitytracker.com/id?1027699 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/79617 - |
Information
Published : 2012-10-31 16:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-4544
Mitre link : CVE-2012-4544
CVE.ORG link : CVE-2012-4544
JSON object : View
CWE
CWE-20
Improper Input Validation