VDB
CVE-2008-5716
CVE-2008-5716
PUBLISHED
CVSS 7.199999809265137 HIGH
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.
EPSS 0.06% · 20.1th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.06%
20.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| citrix | xen | 3.3.0 |
Timeline
- Dec 24, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- xen-xend-xenstore-dos(47668) vdb
- [xen-devel] 20081218 Re: PATCH: Actually make /local/domain/$DOMID readonly to the guest mailing-list
- [xen-devel] 20081218 Re: PATCH: Actually make /local/domain/$DOMID readonly to the guest mailing-list
- [xen-devel] 20081218 Re: PATCH: Actually make /local/domain/$DOMID readonly to the guest mailing-list
- 31499 vdb
- [oss-security] 20081219 CVE Request -- Xen (Upstream patch for CVE-2008-4405 is incomplete) mailing-list
- [xen-devel] 20081218 PATCH: Actually make /local/domain/$DOMID readonly to the guest mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-5716 advisory