CVE Vulnerabilities

CVE-2014-1893

Published: Apr 01, 2014 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.2 MEDIUM
AV:A/AC:M/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1891, CVE-2014-1892, and CVE-2014-1894.

Affected Software

Name Vendor Start Version End Version
Xen Xen * 4.1.6.1 (including)
Xen Xen 3.2.0 (including) 3.2.0 (including)
Xen Xen 3.2.1 (including) 3.2.1 (including)
Xen Xen 3.2.2 (including) 3.2.2 (including)
Xen Xen 3.2.3 (including) 3.2.3 (including)
Xen Xen 3.3.0 (including) 3.3.0 (including)
Xen Xen 3.3.1 (including) 3.3.1 (including)
Xen Xen 3.3.2 (including) 3.3.2 (including)
Xen Xen 3.4.0 (including) 3.4.0 (including)
Xen Xen 3.4.1 (including) 3.4.1 (including)
Xen Xen 3.4.2 (including) 3.4.2 (including)
Xen Xen 3.4.3 (including) 3.4.3 (including)
Xen Xen 3.4.4 (including) 3.4.4 (including)
Xen Xen 4.0.0 (including) 4.0.0 (including)
Xen Xen 4.0.1 (including) 4.0.1 (including)
Xen Xen 4.0.2 (including) 4.0.2 (including)
Xen Xen 4.0.3 (including) 4.0.3 (including)
Xen Xen 4.0.4 (including) 4.0.4 (including)
Xen Xen 4.1.0 (including) 4.1.0 (including)
Xen Xen 4.1.1 (including) 4.1.1 (including)
Xen Xen 4.1.2 (including) 4.1.2 (including)
Xen Xen 4.1.3 (including) 4.1.3 (including)
Xen Xen 4.1.4 (including) 4.1.4 (including)
Xen Xen 4.1.5 (including) 4.1.5 (including)

References