CVE-2012-2625
published 2012-10-31CVE-2012-2625: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of…
PriorityP49low2.7CVSS 2.0
AVAACLAuSCNINAP
EPSS
0.92%
56.3th percentile
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-4 (bookworm) | xen 4.1.3-4 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen-unstable | < 25589\:60f09d1ab1fe | 25589\:60f09d1ab1fe |
CVSS provenance
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv2.7LOW
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87h8-hfg7-gxc3: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4
ghsa_unreviewed·2022-05-14
CVE-2012-2625 [LOW] CWE-20 GHSA-87h8-hfg7-gxc3: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
OSV
CVE-2012-2625: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4
osv·2012-10-31·CVSS 2.7
CVE-2012-2625 [LOW] CVE-2012-2625: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Red Hat
xen: pv bootloader doesn't check the size of the bzip2 or lzma compressed kernel
vendor_redhat·2012-05-04·CVSS 2.7
CVE-2012-2625 [LOW] xen: pv bootloader doesn't check the size of the bzip2 or lzma compressed kernel
xen: pv bootloader doesn't check the size of the bzip2 or lzma compressed kernel
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Debian
CVE-2012-2625: xen - The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2....
vendor_debian·2012·CVSS 2.7
CVE-2012-2625 [LOW] CVE-2012-2625: xen - The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2....
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: resolved (fixed in 4.1.3-4)
trixie: resolved (fixed in 4.1.3-4)
No detection rules found.
No public exploits indexed.
http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1817http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1130.htmlhttp://secunia.com/advisories/49184http://secunia.com/advisories/51413http://www.openwall.com/lists/oss-security/2012/10/26/3http://www.securityfocus.com/bid/53650http://www.securitytracker.com/id?1027090http://xenbits.xensource.com/hg/xen-unstable.hg/rev/60f09d1ab1fehttp://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1817http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1130.htmlhttp://secunia.com/advisories/49184http://secunia.com/advisories/51413http://www.openwall.com/lists/oss-security/2012/10/26/3http://www.securityfocus.com/bid/53650http://www.securitytracker.com/id?1027090http://xenbits.xensource.com/hg/xen-unstable.hg/rev/60f09d1ab1fe
2012-10-31
Published