CVE-2012-2625: Input Validation
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2625?
CVE-2012-2625 is classified as a medium severity vulnerability due to the potential for denial of service through memory consumption.
How do I fix CVE-2012-2625?
To mitigate CVE-2012-2625, users should update to the latest version of Xen beyond the affected versions specified in the vulnerability description.
Who is affected by CVE-2012-2625?
CVE-2012-2625 affects local para-virtualized guest users running specific versions of Xen boot loaders.
What type of attack does CVE-2012-2625 involve?
CVE-2012-2625 involves a denial of service attack vector that exploits large compressed kernel images.
What versions of Xen are affected by CVE-2012-2625?
CVE-2012-2625 affects Xen versions 4.1.0 through 4.2.x before changeset 25589:60f09d1ab1fe.