CVE-2011-3262
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in…
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- citrix/xen
- Source
- cve@mitre.org
References
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00483.htmlPatch
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00491.htmlPatch
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69381
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00483.htmlPatch
- http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00491.htmlPatch
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69381
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.