6.1

CVE-2012-3495

The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CitrixXenserver Version <= 6.0.2
CitrixXenserver Version5.0
CitrixXenserver Version5.5
CitrixXenserver Version5.6
CitrixXenserver Version5.6 Updatefp1
CitrixXenserver Version5.6 Updatesp2
CitrixXenserver Version6.0
XenXen Version4.1.0
XenXen Version4.1.1
XenXen Version4.1.2
XenXen Version4.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.208
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 3.9 8.5
AV:L/AC:L/Au:N/C:P/I:P/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.