Xen 'hvmop _ set_mem_access 'Local Denial of Service Vulnerability
Release date: 2012-4 4
Updated on: 2012-12-07
Affected Systems:
XenSource Xen 4.x
XenSource Xen 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56799
CVE (CAN) ID: CVE-2012-5512
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
In Xen 4.1, the HVMOP_set_mem_access operation handler uses it as an array index before checking the input range, resulting in cross-border access. A malicious client administrator can cause Xen to crash.
<* Source: vendor
Link: http://secunia.com/advisories/51397/
Http://lists.xen.org/archives/html/xen-announce/2012-12/msg00003.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download the patch from the vendor's homepage.
Http://lists.xen.org/archives/html/xen-announce/2012-12/binaFPEoixdQ4.bin
$ Sha256sum xsa28 *. patch
Bytes
Xsa28-4.1.patch
$
Http://xen.xensource.com/