CVE-2014-3714CVE-2014-3714

Affected configuration(s):

cpe:/o:xen:xen:4.4.0:-
cpe:/o:xen:xen:4.4.0:rc1

Date published: 2014-05-19T10:55:12.377-04:00

Date last modified: 2016-10-19T13:03:55.533-04:00

CVSS Score: 3.3

Principal attack vector: LOCAL

Complexity:  MEDIUM

Reference URL: http://www.openwall.com/lists/oss-security/2014/05/14/4

Summary: The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.