CVE-2012-5511
published 2012-12-13CVE-2012-5511: Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of…
PriorityP419medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.43%
35.2th percentile
Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-5 (bookworm) | xen 4.1.3-5 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qfq-67cw-h54c: Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3
ghsa_unreviewed·2022-05-17
CVE-2012-5511 [MEDIUM] CWE-119 GHSA-9qfq-67cw-h54c: Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3
Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.
OSV
CVE-2012-5511: Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3
osv·2012-12-13·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511: Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3
Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.
Red Hat
kernel: xen: several HVM operations do not validate the range of their inputs
vendor_redhat·2012-12-03·CVSS 4.7
CVE-2012-5511 [MEDIUM] kernel: xen: several HVM operations do not validate the range of their inputs
kernel: xen: several HVM operations do not validate the range of their inputs
Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-5511: xen - Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen...
vendor_debian·2012·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511: xen - Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen...
Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.
Scope: local
bookworm: resolved (fixed in 4.1.3-5)
bullseye: resolved (fixed in 4.1.3-5)
forky: resolved (fixed in 4.1.3-5)
sid: resolved (fixed in 4.1.3-5)
trixie: resolved (fixed in 4.1.3-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
bugzilla·2012-12-13·CVSS 4.7
CVE-2012-6333 [MEDIUM] CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6333 to the following vulnerability:
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6333
[2] http://www.openwall.com/lists/oss-security/2012/12/03/10
[3] http://support.citrix.com/article/CTX135777
[4] http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.html
[5] http://www.securityfocus.com/bid/56796
[6] http://www.osvdb.org/88129
[7] http://secunia.com/advisories/51397
[8]
Bugzilla
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
bugzilla·2012-12-03·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field whe
Bugzilla
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
bugzilla·2012-11-16·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
Several HVM control operations do not check the size of their inputs
and can tie up a physical CPU for extended periods of time.
In addition dirty video RAM tracking involves clearing the bitmap
provided by the domain controlling the guest (e.g. dom0 or a
stubdom). If the size of that bitmap is overly large, an intermediate
variable on the hypervisor stack may overflow that stack.
A malicious guest administrator can cause Xen to become unresponsive
or to crash leading in either case to a Denial of Service.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the
http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.debian.org/security/2013/dsa-2636http://www.openwall.com/lists/oss-security/2012/12/03/10http://www.osvdb.org/88129http://www.securityfocus.com/bid/56796https://exchange.xforce.ibmcloud.com/vulnerabilities/80484http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.debian.org/security/2013/dsa-2636http://www.openwall.com/lists/oss-security/2012/12/03/10http://www.osvdb.org/88129http://www.securityfocus.com/bid/56796https://exchange.xforce.ibmcloud.com/vulnerabilities/80484
2012-12-13
Published