Xen mov_to_rr RID Local Security Bypass Vulnerability
BID:26716
Info
Xen mov_to_rr RID Local Security Bypass Vulnerability
| Bugtraq ID: | 26716 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6207 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2007 12:00AM |
| Updated: | Mar 13 2008 02:41AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
XenSource Xen 3.1.1 XenSource Xen 3.0.3 XenSource Xen 3.0 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server |
| Not Vulnerable: |
XenSource Xen 3.1.2 |
Discussion
Xen mov_to_rr RID Local Security Bypass Vulnerability
Xen is prone to a local security-bypass vulnerability because it fails to validate user-supplied input.
Local attackers can leverage this issue to read memory from VT-i domains other than the one they have access to. This could allow attackers to obtain potentially sensitive information that could aid in further attacks.
Versions prior to Xen 3.1.2 on IA64 platforms are vulnerable.
Xen is prone to a local security-bypass vulnerability because it fails to validate user-supplied input.
Local attackers can leverage this issue to read memory from VT-i domains other than the one they have access to. This could allow attackers to obtain potentially sensitive information that could aid in further attacks.
Versions prior to Xen 3.1.2 on IA64 platforms are vulnerable.
Exploit / POC
Xen mov_to_rr RID Local Security Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen mov_to_rr RID Local Security Bypass Vulnerability
Solution:
A patch is available in the vendor's Mercurial repository. Please see the references for more information.
Solution:
A patch is available in the vendor's Mercurial repository. Please see the references for more information.
References
Xen mov_to_rr RID Local Security Bypass Vulnerability
References:
References:
- [Xen-ia64-devel] PATCH: check r2 value for VTi mov rr[r3]=r2 (XenSource)
- Changelog for xen-3.1-testing (XenSource)
- Xen Project Homepage (Xen Project)
- RHSA-2008:0154-15 kernel security and bug fix update (Red Hat)