2.1
CVSSv2

CVE-2012-4544

Published: 31/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The PV domain builder in Xen 4.2 and previous versions does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.1.1

xen xen 4.1.0

xen xen

xen xen 4.1.3

xen xen 4.1.2

Vendor Advisories

Synopsis Moderate: xen security update Type/Severity Security Advisory: Moderate Topic Updated xen packages that fix one security issue are now available forRed Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring S ...
Debian Bug report logs - #688125 CVE-2012-2625 / CVE-2012-4544 Package: xen; Maintainer for xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 19 Sep 2012 15:39:07 UTC Severity: important Tags: security Fixed in version 413-4 Done: Bastian B ...
Multiple vulnerabilities have been discovered in the Xen hypervisor The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2012-4544 Insufficient validation of kernel or ramdisk sizes in the Xen PV domain builder could result in denial of service CVE-2012-5511 Several HVM control operations performed ...