CVE-2007-6207: Input Validation
Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for movtorr, which allows a VTi domain to read memory of other domains.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6207?
The severity of CVE-2007-6207 is generally considered high due to potential unauthorized memory access between virtualized domains.
How do I fix CVE-2007-6207?
To fix CVE-2007-6207, upgrade to Xen version 3.1.2 or later, as these versions implement the necessary checks for RID values.
Which systems are affected by CVE-2007-6207?
CVE-2007-6207 affects Xen versions 3.x, specifically on IA64 systems, up to and including version 3.1.1.
What types of attacks can exploit CVE-2007-6207?
CVE-2007-6207 can be exploited by a VTi domain to read the memory of other domains, potentially leading to sensitive data exposure.
Is CVE-2007-6207 a local or remote vulnerability?
CVE-2007-6207 is primarily a local vulnerability, requiring access to the virtualization environment to exploit.