CVE Vulnerabilities

CVE-2011-1583

Published: Aug 12, 2011 | Modified: Aug 24, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6 IMPORTANT
AV:L/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

Affected Software

Name Vendor Start Version End Version
Xen Citrix 3.2.0 (including) 3.2.0 (including)
Xen Citrix 3.3.0 (including) 3.3.0 (including)
Xen Citrix 4.0.0 (including) 4.0.0 (including)
Xen Citrix 4.1.0 (including) 4.1.0 (including)
Red Hat Enterprise Linux 5 RedHat xen-0:3.0.3-120.el5_6.2 *
Xen Ubuntu upstream *
Xen-3.1 Ubuntu hardy *
Xen-3.2 Ubuntu hardy *
Xen-3.3 Ubuntu lucid *
Xen-3.3 Ubuntu maverick *
Xen-3.3 Ubuntu natty *

References