Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
BID:56797
Info
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 56797 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5513 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 04 2012 12:00AM |
| Updated: | Apr 13 2015 10:12PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
XenSource Xen 4.1.2 XenSource Xen 4.1.1 XenSource Xen 3.3.1 XenSource Xen 3.3 XenSource Xen 3.2 XenSource Xen 3.1.2 XenSource Xen 3.1.1 XenSource Xen 3.0.3 XenSource Xen 4.2 RC XenSource Xen 4.2 XenSource Xen 4.1 XenSource Xen 4.0 XenSource Xen 3.4 XenSource Xen 3.0 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 LTSS SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Suse Linux Enterprise Desktop 10 SP4 S.u.S.E. openSUSE 12.2 S.u.S.E. openSUSE 12.1 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 5 OpenVZ Project OpenVZ 028stab098.1 OpenVZ Project OpenVZ 028stab095.1 OpenVZ Project OpenVZ 028stab092.2 OpenVZ Project OpenVZ 028stab091.1 OpenVZ Project OpenVZ 028stab089.1 OpenVZ Project OpenVZ 028stab085.2 OpenVZ Project OpenVZ 028stab081.1 Gentoo Linux Citrix XenServer 6.0.2 Citrix XenServer 6.1 Citrix XenServer 6.0 Citrix XenServer 5.6 Citrix XenServer 5.5 Citrix XenServer 5.0 CentOS CentOS 5 |
| Not Vulnerable: |
OpenVZ Project OpenVZ 028stab106.2 |
Discussion
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
Xen is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with elevated privileges. Failed attacks will likely cause denial-of-service conditions.
Xen is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with elevated privileges. Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
References:
References:
- Download/kernel/rhel5/028stab106.2 (OpenVZ)
- Xen Project Homepage (Xen Project)
- Xen Security Advisory 29 (CVE-2012-5513) - XENMEM_exchange may overwrite hypervi (Sec Lists)
- Citrix XenServer Multiple Security Updates (Citrix Systems)