Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
BID:29186
Info
Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
| Bugtraq ID: | 29186 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1944 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2008 12:00AM |
| Updated: | May 14 2008 05:35PM |
| Credit: | Daniel P. Berrange |
| Vulnerable: |
XenSource Xen 3.0.3 XenSource Xen 3.0 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server |
| Not Vulnerable: | |
Discussion
Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
Xen is prone to a denial-of-service vulnerability because the application fails to adequately verify the format of user-supplied data.
An attacker can leverage this issue to cause denial-of-service conditions or to compromise the privileged domain (Dom0).
Xen is prone to a denial-of-service vulnerability because the application fails to adequately verify the format of user-supplied data.
An attacker can leverage this issue to cause denial-of-service conditions or to compromise the privileged domain (Dom0).
Exploit / POC
Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
Solution:
Fixes are available. Please see the references for more information.
Solution:
Fixes are available. Please see the references for more information.
References
Xen Para-Virtualized Framebuffer Message Format Denial Of Service Vulnerability
References:
References:
- Xen Project Homepage (Xen Project)
- RHSA-2008:0194-20 xen security and bug fix update (Red Hat)