Buffer overflow in Xen - CVE-2014-4021

 

Buffer overflow in Xen - CVE-2014-4021

Published: June 18, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41543
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2014-4021
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Xen Project
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a remote #AU# to gain access to sensitive information.

Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.


How to mitigate CVE-2014-4021

Install update from vendor's website.

Sources