CVE-2014-1892: Buffer Overflow
Published Apr 1, 2014
·Updated
Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a different vulnerability than CVE-2014-1891, CVE-2014-1893, and CVE-2014-1894.
Affected Software
20 affected components
XEN Xen=3.3.0
XEN Xen=3.3.1
XEN Xen=3.3.2
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
Event History
Apr 1, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·06:35 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1892?
CVE-2014-1892 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2014-1892?
To fix CVE-2014-1892, update your Xen installation to the latest version that addresses this vulnerability.
3
Which software versions are affected by CVE-2014-1892?
CVE-2014-1892 affects Xen versions 3.3.0 through 4.1.6.1 with XSM enabled.
4
Can CVE-2014-1892 be exploited remotely?
CVE-2014-1892 requires local access to the system to exploit, making it less of a remote threat.
5
What are the potential impacts of CVE-2014-1892?
The primary impact of CVE-2014-1892 is a denial of service, leading to system instability or unavailability.