CVE Database
/

CVE-2014-1950

Back to search

CVE-2014-1950

Published: Feb 14, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2014:0373
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0372
vendor-advisory
x_refsource_SUSE
DSA-3006
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now