Xen 'xc_cpupool_getinfo()' Function Use After Free Memory Corruption Vulnerability
BID:65529
Info
Xen 'xc_cpupool_getinfo()' Function Use After Free Memory Corruption Vulnerability
| Bugtraq ID: | 65529 |
| Class: | Unknown |
| CVE: |
CVE-2014-1950 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2014 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Coverity Scan |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 11 SP2 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Xen 'xc_cpupool_getinfo()' Function Use After Free Memory Corruption Vulnerability
Xen is prone to a memory-corruption vulnerability.
Successful exploits may allow attackers to execute arbitrary code with elevated privileges. Failed attacks may cause a denial-of-service condition.
Xen 4.1 and above are vulnerable.
Xen is prone to a memory-corruption vulnerability.
Successful exploits may allow attackers to execute arbitrary code with elevated privileges. Failed attacks may cause a denial-of-service condition.
Xen 4.1 and above are vulnerable.
Solution / Fix
Xen 'xc_cpupool_getinfo()' Function Use After Free Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen 'xc_cpupool_getinfo()' Function Use After Free Memory Corruption Vulnerability
References:
References:
- XenSource Homepage (XenSource)