CVE Database
/

CVE-2012-4544

Back to search

CVE-2012-4544

Published: Oct 31, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
51071
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-17408
vendor-advisory
x_refsource_FEDORA
51413
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-17204
vendor-advisory
x_refsource_FEDORA
SUSE-SU-2012:1486
vendor-advisory
x_refsource_SUSE
DSA-2636
vendor-advisory
x_refsource_DEBIAN
xen-pvdomainbuilder-dos(79617)
vdb-entry
x_refsource_XF
FEDORA-2012-17135
vendor-advisory
x_refsource_FEDORA
56289
vdb-entry
x_refsource_BID
1027699
vdb-entry
x_refsource_SECTRACK
RHSA-2013:0241
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2012:1572
vendor-advisory
x_refsource_SUSE
86619
vdb-entry
x_refsource_OSVDB
SUSE-SU-2012:1487
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
51352
third-party-advisory
x_refsource_SECUNIA
51324
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:1573
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now