CVE-2013-2072: Buffer Overflow
Buffer overflow in the Python bindings for the xcvcpusetaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2072?
The severity of CVE-2013-2072 is classified as high due to the potential for local exploitation leading to memory corruption and privilege escalation.
How does CVE-2013-2072 affect Xen 4.0.x to 4.2.x?
CVE-2013-2072 affects these versions by allowing local administrators to exploit a buffer overflow in the xc_vcpu_setaffinity call.
How can I mitigate CVE-2013-2072?
Mitigation of CVE-2013-2072 can be achieved by applying the appropriate security patches provided for the impacted versions of Xen.
What are the potential consequences of exploiting CVE-2013-2072?
Exploitation of CVE-2013-2072 can lead to a denial of service due to the xend toolstack crash and could potentially allow privilege escalation.
Which versions of Xen are vulnerable to CVE-2013-2072?
Vulnerable versions of Xen include 4.0.0 through 4.2.2.