CVE-2013-4416: Buffer Overflow
Published Nov 2, 2013
·Updated
The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.
Affected Software
13 affected components
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
XEN Xen=4.3.1
Event History
Nov 2, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Sep 3, 2025
Data Sourced
via Microsoft·11:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-4416?
CVE-2013-4416 has a medium severity rating due to its potential to cause local denial of service.
2
How do I fix CVE-2013-4416?
To fix CVE-2013-4416, upgrade to a patched version of Xen that addresses this vulnerability.
3
What versions of Xen are affected by CVE-2013-4416?
CVE-2013-4416 affects Xen versions 4.1.x, 4.2.x, and 4.3.x.
4
What kind of denial of service does CVE-2013-4416 cause?
CVE-2013-4416 allows local guest domains to cause a denial of service by shutting down the domain via a large message reply.
5
Is CVE-2013-4416 exploitable remotely?
CVE-2013-4416 is not remotely exploitable as it requires local access to the guest domain.