CVE Database
/

CVE-2008-4405

Back to search

CVE-2008-4405

Published: Oct 3, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2008-2709
vdb-entry
x_refsource_VUPEN
MDVSA-2009:016
vendor-advisory
x_refsource_MANDRIVA
32064
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2009:015
vendor-advisory
x_refsource_SUSE
[oss-security] 20080930 CVE Request (xen)
mailing-list
x_refsource_MLIST
RHSA-2009:0003
vendor-advisory
x_refsource_REDHAT
31499
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:10627
vdb-entry
signature
x_refsource_OVAL
1020955
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now