Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
BID:30834
Info
Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
| Bugtraq ID: | 30834 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3687 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 22 2008 12:00AM |
| Updated: | Aug 29 2008 02:05AM |
| Credit: | Rafal Wojtczuk |
| Vulnerable: |
XenSource Xen 3.2 |
| Not Vulnerable: |
XenSource Xen 3.3 |
Discussion
Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
Xen is prone to multiple local buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit these issues to execute arbitrary code and elevate privileges. Failed attempts may result in a denial-of-service condition.
These issues affect Xen 3.2.0; other versions may also be affected.
Xen is prone to multiple local buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit these issues to execute arbitrary code and elevate privileges. Failed attempts may result in a denial-of-service condition.
These issues affect Xen 3.2.0; other versions may also be affected.
Exploit / POC
Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Xen 'XSM:Flask' Module Multiple Local Buffer Overflow Vulnerabilities
References:
References:
- [XSM][FLASK] Argument handling bugs in XSM:FLASK (XenSource)
- Xen Project Homepage (Xen Project)