Vulnerability CVE-2008-4405


Published: 2008-10-03   Modified: 2012-02-12

Description:
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

Vendor: Citrix
Product: XEN 
Version: 3.0.3;

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=464818
https://bugzilla.redhat.com/show_bug.cgi?id=464817
https://bugzilla.redhat.com/show_bug.cgi?id=464817
http://xenbits.xensource.com/staging/xen-3.3-testing.hg?rev/e0e17216ba70
http://www.vupen.com/english/advisories/2008/2709
http://www.securitytracker.com/id?1020955
http://www.securityfocus.com/bid/31499
http://www.openwall.com/lists/oss-security/2008/10/04/3
http://www.mandriva.com/security/advisories?name=MDVSA-2009:016
http://secunia.com/advisories/32064
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10627
http://openwall.com/lists/oss-security/2008/09/30/6
http://lists.xensource.com/archives/html/xen-devel/2008-09/msg00994.html
http://lists.xensource.com/archives/html/xen-devel/2008-09/msg00992.html
http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html

Related CVE
CVE-2014-3798
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
CVE-2019-12292
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
CVE-2018-18571
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM...
CVE-2019-12044
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10...
CVE-2019-11634
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVE-2019-7218
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first au...
CVE-2019-7217
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
CVE-2019-6485
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 bef...

Copyright 2019, cxsecurity.com

 

Back to Top