CVE-2008-5716: High severity Citrix Xen vulnerability
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous setpermissions calls in the fix for CVE-2008-4405.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5716?
CVE-2008-5716 has been classified as a high severity vulnerability due to its potential to cause denial of service and unspecified other impacts.
How do I fix CVE-2008-5716?
To mitigate CVE-2008-5716, upgrade to a patched version of Xen beyond 3.3.0 that addresses this vulnerability.
What systems are affected by CVE-2008-5716?
CVE-2008-5716 specifically affects Xen version 3.3.0 installed on affected systems.
What types of attacks are possible with CVE-2008-5716?
CVE-2008-5716 may allow guest OS users to perform denial of service attacks by writing to system-critical files.
Is there a workaround for CVE-2008-5716?
There are no known workarounds for CVE-2008-5716 other than upgrading to a secure version of Xen.