Vulnerability CVE-2011-1583: Information

Description

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

Published: Aug. 12, 2011
Modified: Aug. 24, 2011
Error type identifier: CWE-189

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:citrix:xen:3.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:citrix:xen:3.3.0:*:*:*:*:*:*:*

      cpe:2.3:a:citrix:xen:4.1.0:*:*:*:*:*:*:*

      cpe:2.3:a:citrix:xen:4.0.0:*:*:*:*:*:*:*