Back to search
CVE-2012-3494
Published: Nov 23, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
55082
third-party-advisory
x_refsource_SECUNIA
50530
third-party-advisory
x_refsource_SECUNIA
51413
third-party-advisory
x_refsource_SECUNIA
GLSA-201309-24
vendor-advisory
x_refsource_GENTOO
SUSE-SU-2012:1135
vendor-advisory
x_refsource_SUSE
https://bugzilla.redhat.com/show_bug.cgi?id=851139
x_refsource_MISC
openSUSE-SU-2012:1572
vendor-advisory
x_refsource_SUSE
50472
third-party-advisory
x_refsource_SECUNIA
55400
vdb-entry
x_refsource_BID
[oss-security] 20120905 Xen Security Advisory 12 (CVE-2012-3494) - hypercall set_debugreg vulnerability
mailing-list
x_refsource_MLIST
SUSE-SU-2012:1162
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:1174
vendor-advisory
x_refsource_SUSE
GLSA-201604-03
vendor-advisory
x_refsource_GENTOO
xen-setdebugreg-dos(78265)
vdb-entry
x_refsource_XF
SUSE-SU-2012:1132
vendor-advisory
x_refsource_SUSE
http://support.citrix.com/article/CTX134708
x_refsource_CONFIRM
[Xen-announce] 20120905 Xen Security Advisory 12 (CVE-2012-3494) - hypercall set_debugreg vulnerability
mailing-list
x_refsource_MLIST
SUSE-SU-2012:1129
vendor-advisory
x_refsource_SUSE
SUSE-SU-2012:1133
vendor-advisory
x_refsource_SUSE
85197
vdb-entry
x_refsource_OSVDB
1027479
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2012:1573
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:1172
vendor-advisory
x_refsource_SUSE
DSA-2544
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now