Sploitus

CVE-2008-4405

1 known exploit for CVE-2008-4405

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.

Affected products
Red Hat, Xen
Citrix Xen
= 3.0.3
Fix
Available
CVSS 2.0
7.2 HIGH
EPSS
1.0% (62th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2008-10-03
CVE-2008-4405 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2008-4405

Proof-of-concept code and exploit modules indexed by Sploitus