CVE Vulnerabilities

CVE-2011-1583

Published: Aug 12, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6 IMPORTANT
AV:L/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

Affected Software

NameVendorStart VersionEnd Version
XenCitrix3.2.0 (including)3.2.0 (including)
XenCitrix3.3.0 (including)3.3.0 (including)
XenCitrix4.0.0 (including)4.0.0 (including)
XenCitrix4.1.0 (including)4.1.0 (including)
Red Hat Enterprise Linux 5RedHatxen-0:3.0.3-120.el5_6.2*
XenUbuntuupstream*
Xen-3.1Ubuntuhardy*
Xen-3.2Ubuntuhardy*
Xen-3.3Ubuntulucid*
Xen-3.3Ubuntumaverick*
Xen-3.3Ubuntunatty*

References