Back to search
CVE-2012-4544
Published: Oct 31, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
51071
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-17408
vendor-advisory
x_refsource_FEDORA
51413
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-17204
vendor-advisory
x_refsource_FEDORA
SUSE-SU-2012:1486
vendor-advisory
x_refsource_SUSE
DSA-2636
vendor-advisory
x_refsource_DEBIAN
xen-pvdomainbuilder-dos(79617)
vdb-entry
x_refsource_XF
FEDORA-2012-17135
vendor-advisory
x_refsource_FEDORA
56289
vdb-entry
x_refsource_BID
1027699
vdb-entry
x_refsource_SECTRACK
RHSA-2013:0241
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2012:1572
vendor-advisory
x_refsource_SUSE
86619
vdb-entry
x_refsource_OSVDB
SUSE-SU-2012:1487
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
51352
third-party-advisory
x_refsource_SECUNIA
51324
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:1573
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now