CVE-2012-5525: Medium severity xen xapi vulnerability
Published Dec 13, 2012
·Updated
The getpagefromgfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.
Affected Software
1 affected component
XEN Xen=4.2.0
Event History
Dec 13, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5525?
CVE-2012-5525 is considered a denial of service vulnerability.
2
How does CVE-2012-5525 affect Xen 4.2?
CVE-2012-5525 allows local PV guest OS administrators to crash the Xen hypervisor by exploiting a buffer over-read.
3
What versions of Xen are affected by CVE-2012-5525?
CVE-2012-5525 specifically affects Xen version 4.2.0.
4
How can CVE-2012-5525 be mitigated?
To mitigate CVE-2012-5525, it is recommended to upgrade to a patched version of Xen that addresses this vulnerability.
5
Who is impacted by CVE-2012-5525?
CVE-2012-5525 impacts local administrators of paravirtualized (PV) guest operating systems running on Xen 4.2.