CVE-2014-3715: Buffer Overflow
Published May 19, 2014
·Updated
Buffer overflow in Xen 4.4.x allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit guest kernel, related to searching for an appended DTB.
Affected Software
2 affected components
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
Remediation
Patch Available
Event History
May 19, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3715?
CVE-2014-3715 has a high severity rating due to the potential for local users to read sensitive system memory or cause a denial of service.
2
How do I fix CVE-2014-3715?
To fix CVE-2014-3715, upgrade to a patched version of Xen that addresses this vulnerability.
3
Who is affected by CVE-2014-3715?
CVE-2014-3715 affects local users of Xen 4.4.0 and its release candidates that run crafted 32-bit guest kernels.
4
What are the consequences of exploiting CVE-2014-3715?
Exploitation of CVE-2014-3715 can lead to reading sensitive memory information or crashing the Xen hypervisor.
5
What versions of Xen are vulnerable according to CVE-2014-3715?
According to CVE-2014-3715, Xen versions 4.4.0 and 4.4.0-rc1 are vulnerable.