Back

HIGH

xen: Incomplete upstream fix for CVE-2008-4405

Published Dec 24, 2008

Description

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of Xen as shipped with Red Hat Enterprise Linux 5. Security update released to address CVE-2008-4405 - RHSA-2009:0003 - contained correct patch which did not introduce this problem and resolved the original issue.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2008
Updated Aug 7, 2024
Reserved Dec 24, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 18, 2008