[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-4247Date: (C)2011-01-10   (M)2024-01-04


The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.5
Exploit Score: 5.1
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
http://www.securityfocus.com/archive/1/520102/100/0/threaded
SECUNIA-35093
SECUNIA-42789
BID-45029
SECUNIA-46397
ADV-2011-0024
RHSA-2011:0004
http://www.openwall.com/lists/oss-security/2010/11/23/1
http://www.openwall.com/lists/oss-security/2010/11/24/8
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
http://xenbits.xensource.com/linux-2.6.18-xen.hg?rev/7070d34f251c
http://xenbits.xensource.com/linux-2.6.18-xen.hg?rev/77f831cbb91d
https://bugzilla.redhat.com/show_bug.cgi?id=656206

CPE    1
cpe:/o:linux:linux_kernel:2.6.18
CWE    1
CWE-20
OVAL    4
oval:org.secpod.oval:def:700555
oval:org.secpod.oval:def:500255
oval:org.secpod.oval:def:201465
oval:org.secpod.oval:def:201476
...

© SecPod Technologies