6.9
CVSSv2

CVE-2011-1583

Published: 12/08/2011 Updated: 24/08/2011
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix xen 3.2.0

citrix xen 3.3.0

citrix xen 4.0.0

citrix xen 4.1.0

Vendor Advisories

Several vulnerabilities were discovered in the Xen virtual machine hypervisor CVE-2011-1166 A 64-bit guest can get one of its vCPUs into non-kernel mode without first providing a valid non-kernel pagetable, thereby locking up the host system CVE-2011-1583, CVE-2011-3262 Local users can cause a denial of service and possibly execute arb ...