Xen SAHF Emulation Denial of Service Vulnerability
BID:49375
Info
Xen SAHF Emulation Denial of Service Vulnerability
| Bugtraq ID: | 49375 |
| Class: | Design Error |
| CVE: |
CVE-2011-2519 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 30 2011 12:00AM |
| Updated: | Apr 03 2013 06:07PM |
| Credit: | Eugene Teo |
| Vulnerable: |
XenSource Xen 3.1.2 XenSource Xen 3.1.1 XenSource Xen 3.0.3 XenSource Xen 3.0 VMWare ESX 4.1 VMWare ESX 4.0 RedHat Enterprise Linux 5.0 RedHat Enterprise Linux 5 Client Red Hat Enterprise Linux EUS 5.6.z server Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
Xen SAHF Emulation Denial of Service Vulnerability
Xen is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the host operating system to consume excessive amounts of resources, denying service to legitimate users.
Xen is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the host operating system to consume excessive amounts of resources, denying service to legitimate users.
Exploit / POC
Xen SAHF Emulation Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen SAHF Emulation Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xen SAHF Emulation Denial of Service Vulnerability
References:
References:
- Bug 718882 - (CVE-2011-2519) CVE-2011-2519 kernel: xen: x86_emulate: fix SAHF em (Red Hat Bugzilla)
- Download/kernel/rhel5/028stab094.3 (OpenVZ)
- VMSA-2012-0001 (VMWare)
- xen-3.1-testing.hg (Keir Fraser)
- XenSource Homepage (XenSource)
- Avaya ASA-2011-319 kernel security and bug fix update (RHSA-2011-1212) (avaya)