CVE-2015-3259
published 2015-07-16CVE-2015-3259: Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long…
PriorityP425medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.39%
32.1th percentile
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: xl command line config handling stack overflow (XSA-137)
vendor_redhat·2015-07-07·CVSS 6.8
CVE-2015-3259 [MEDIUM] CWE-20 xen: xl command line config handling stack overflow (XSA-137)
xen: xl command line config handling stack overflow (XSA-137)
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
Statement: Not vulnerable.
This issue does not affect the Xen packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-3259: xen - Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through ...
vendor_debian·2015·CVSS 6.8
CVE-2015-3259 [MEDIUM] CVE-2015-3259: xen - Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through ...
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
GHSA
GHSA-8m5p-xp4x-w5vh: Stack-based buffer overflow in the xl command line utility in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-3259 [MEDIUM] GHSA-8m5p-xp4x-w5vh: Stack-based buffer overflow in the xl command line utility in Xen 4
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
OSV
CVE-2015-3259: Stack-based buffer overflow in the xl command line utility in Xen 4
osv·2015-07-16·CVSS 6.8
CVE-2015-3259 [MEDIUM] CVE-2015-3259: Stack-based buffer overflow in the xl command line utility in Xen 4
Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3279 cups-filters: texttopdf integer overflow
bugzilla·2015-07-03·CVSS 6.8
CVE-2015-3279 [MEDIUM] CVE-2015-3279 cups-filters: texttopdf integer overflow
CVE-2015-3279 cups-filters: texttopdf integer overflow
An integer overflow flaw leading to a heap-based buffer overflow was
discovered in the way the texttopdf utility of cups-filter processed
print jobs with a specially crafted line size. An attacker being able
to submit print jobs could exploit this flaw to crash texttopdf or,
possibly, execute arbitrary code with the privileges of the 'lp' user.
Patch:
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7365
Discussion:
Comment in
http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7365
claims it's CVE-2015-3259 (not 3279).
---
That was my mistake. The correct name is CVE-2015-3279.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA
Bugzilla
CVE-2015-3259 xen: xl command line config handling stack overflow (XSA-137)
bugzilla·2015-07-01·CVSS 6.8
CVE-2015-3259 [MEDIUM] CVE-2015-3259 xen: xl command line config handling stack overflow (XSA-137)
CVE-2015-3259 xen: xl command line config handling stack overflow (XSA-137)
ISSUE DESCRIPTION
The xl command line utility mishandles long configuration values when passed as command line arguments, with a buffer overrun.
VULNERABLE SYSTEMS
Systems built on top of xl which pass laundered or checked (but otherwise untrusted) configuration values onto xl's command line, without restricting their length, are vulnerable.
We are not presently aware of any publicly distributed production software which exposes the xl vulnerability. However it is sufficiently simple to create such an arrangement that it might be done locally in an attempt to grant partial management access to particular domains.
Systems using the libxl library directly, without using xl, are not vulnerable. Systems using too
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.htmlhttp://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/75573http://www.securitytracker.com/id/1032973http://xenbits.xen.org/xsa/advisory-137.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.htmlhttp://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/75573http://www.securitytracker.com/id/1032973http://xenbits.xen.org/xsa/advisory-137.htmlhttps://security.gentoo.org/glsa/201604-03
2015-07-16
Published