CVE-2015-3259: Buffer Overflow
Published Jul 16, 2015
·Updated
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
Affected Software
19 affected components
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.3.4
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
XEN Xen=4.4.1
XEN Xen=4.4.2
XEN Xen=4.5.0
Remediation
Patch Available
Event History
Jul 16, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3259?
CVE-2015-3259 has a medium severity rating due to its potential to allow privilege escalation for local guest administrators.
2
How do I fix CVE-2015-3259?
To fix CVE-2015-3259, ensure you upgrade to a version of Xen that is not vulnerable, specifically 4.5.0 or later.
3
Who is affected by CVE-2015-3259?
CVE-2015-3259 affects local guest administrators using Xen versions 4.1.x through 4.5.x.
4
What type of vulnerability is CVE-2015-3259?
CVE-2015-3259 is a stack-based buffer overflow vulnerability.
5
Can CVE-2015-3259 be exploited remotely?
No, CVE-2015-3259 requires local access to the system to exploit the vulnerability.