Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-3495


The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.


Published

2012-11-23T20:55:03.150

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

8.5

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application citrix xenserver ≤ 6.0.2 Yes
Application citrix xenserver 5.0 Yes
Application citrix xenserver 5.5 Yes
Application citrix xenserver 5.6 Yes
Application citrix xenserver 5.6 Yes
Application citrix xenserver 5.6 Yes
Application citrix xenserver 6.0 Yes
Operating System xen xen 4.1.0 Yes
Operating System xen xen 4.1.1 Yes
Operating System xen xen 4.1.2 Yes
Operating System xen xen 4.1.3 Yes

References