xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VMs write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xen | Citrix | 3.0.3 (including) | 3.0.3 (including) |
Red Hat Enterprise Linux 5 | RedHat | xen-0:3.0.3-64.el5_2.9 | * |
Xen | Ubuntu | dapper | * |
Xen-3.0 | Ubuntu | feisty | * |
Xen-3.1 | Ubuntu | gutsy | * |
Xen-3.1 | Ubuntu | hardy | * |
Xen-3.1 | Ubuntu | intrepid | * |
Xen-3.2 | Ubuntu | hardy | * |
Xen-3.3 | Ubuntu | intrepid | * |
Xen-3.3 | Ubuntu | jaunty | * |
Xen-3.3 | Ubuntu | karmic | * |
Xen-3.3 | Ubuntu | lucid | * |
Xen-3.3 | Ubuntu | maverick | * |
Xen-3.3 | Ubuntu | natty | * |