Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
BID:29183
Info
Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
| Bugtraq ID: | 29183 |
| Class: | Design Error |
| CVE: |
CVE-2008-1943 |
| Remote: | No |
| Local: | Yes |
| Published: | May 13 2008 12:00AM |
| Updated: | Oct 15 2008 07:27PM |
| Credit: | Markus Armbruster |
| Vulnerable: |
XenSource Xen 3.2 XenSource Xen 3.1.2 XenSource Xen 3.1.1 XenSource Xen 3.0.3 XenSource Xen 3.0 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 server |
| Not Vulnerable: | |
Discussion
Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
Xen is prone to a local buffer-overflow vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the privileged domain (Dom0). Failed attempts will likely cause denial-of-service conditions.
Xen is prone to a local buffer-overflow vulnerability.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the privileged domain (Dom0). Failed attempts will likely cause denial-of-service conditions.
Exploit / POC
Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
Details on exploiting this issue on certain architectures are available; please see the references for more information.
Details on exploiting this issue on certain architectures are available; please see the references for more information.
Solution / Fix
Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
Solution:
Fixes are available in the Xen repository. Please see the references for more information.
Solution:
Fixes are available in the Xen repository. Please see the references for more information.
References
Xen Para Virtualized Frame Buffer Backend Local Buffer Overflow Vulnerability
References:
References:
- Adventures with a certain Xen vulnerability (in the PVFB backend) (Rafal Wojtczuk)
- changeset: ioemu: Fix PVFB backend to validate frontend's frame buffer descripti (XenSource)
- revision 17630 tools/ioemu/hw/xenfb.c (XenSource)
- revision 17643: tools/ioemu/hw/xenfb.c (XenSource)
- Xen Project Homepage (Xen Project)
- Paper: Adventures with a certain Xen vulnerability (Joanna Rutkowska
) - RHSA-2008:0194-20 xen security and bug fix update (Red Hat)