Vulnerabilidad en Xen (CVE-2012-3494)
Gravedad CVSS v2.0:
BAJA
Tipo:
CWE-264
Permisos, privilegios y/o control de acceso
Fecha de publicación:
23/11/2012
Última modificación:
11/04/2025
Descripción
La hiperllamada et_debugreg en include/asm-x86/debugreg.h en Xen v4.0, v4.1, y v4.2, y Citrix XenServer v6.0.2 y anteriores, cuando se ejecuta sobre systemas x86-64, permite a usuarios locales del SO invitado generar una denegación de servicio (caída del host) mediante la escritura de ciertos bits reservados para el registro de control DR
Impacto
Puntuación base 2.0
2.10
Gravedad 2.0
BAJA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:citrix:xenserver:*:-:*:*:*:*:x64:* | 6.0.2 (incluyendo) | |
| cpe:2.3:a:citrix:xenserver:*:-:*:*:*:*:x86:* | 6.0.2 (incluyendo) | |
| cpe:2.3:o:xen:xen:4.0.0:-:*:*:*:*:x64:* | ||
| cpe:2.3:o:xen:xen:4.0.0:-:*:*:*:*:x86:* | ||
| cpe:2.3:o:xen:xen:4.1.0:-:*:*:*:*:x64:* | ||
| cpe:2.3:o:xen:xen:4.1.0:-:*:*:*:*:x86:* | ||
| cpe:2.3:o:xen:xen:4.2.0:-:*:*:*:*:x64:* | ||
| cpe:2.3:o:xen:xen:4.2.0:-:*:*:*:*:x86:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
- http://lists.xen.org/archives/html/xen-announce/2012-09/msg00000.html
- http://osvdb.org/85197
- http://secunia.com/advisories/50472
- http://secunia.com/advisories/50530
- http://secunia.com/advisories/51413
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- http://support.citrix.com/article/CTX134708
- http://wiki.xen.org/wiki/Security_Announcements#XSA-12_hypercall_set_debugreg_vulnerability
- http://www.debian.org/security/2012/dsa-2544
- http://www.openwall.com/lists/oss-security/2012/09/05/5
- http://www.securityfocus.com/bid/55400
- http://www.securitytracker.com/id?1027479=
- https://bugzilla.redhat.com/show_bug.cgi?id=851139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78265
- https://security.gentoo.org/glsa/201604-03
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
- http://lists.xen.org/archives/html/xen-announce/2012-09/msg00000.html
- http://osvdb.org/85197
- http://secunia.com/advisories/50472
- http://secunia.com/advisories/50530
- http://secunia.com/advisories/51413
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- http://support.citrix.com/article/CTX134708
- http://wiki.xen.org/wiki/Security_Announcements#XSA-12_hypercall_set_debugreg_vulnerability
- http://www.debian.org/security/2012/dsa-2544
- http://www.openwall.com/lists/oss-security/2012/09/05/5
- http://www.securityfocus.com/bid/55400
- http://www.securitytracker.com/id?1027479=
- https://bugzilla.redhat.com/show_bug.cgi?id=851139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78265
- https://security.gentoo.org/glsa/201604-03



