1.9
CVSSv2

CVE-2012-3432

Published: 03/12/2012 Updated: 11/10/2013
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 3.3.0

xen xen 4.1.1

xen xen 4.0.2

xen xen 4.0.1

xen xen 4.1.3

xen xen 4.1.2

xen xen 4.1.0

xen xen 4.2.0

xen xen 4.0.0

xen xen 4.0.4

xen xen 4.0.3

Vendor Advisories

Debian Bug report logs - #683279 CVE-2012-3432 Package: xen; Maintainer for xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Jul 2012 13:27:02 UTC Severity: important Tags: security Fixed in versions xen/401-53, xen/413-1 ...