CVE-2008-5716

Publication date 24 December 2008

Last updated 24 July 2024


Ubuntu priority

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.

Status

Package Ubuntu Release Status
xen 8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper
Not affected
xen-3.0 8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release
xen-3.1 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper Not in release
xen-3.2 8.10 intrepid Not in release
8.04 LTS hardy
Not affected
7.10 gutsy Not in release
6.06 LTS dapper Not in release
xen-3.3 8.10 intrepid
Not affected
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release
xen-unstable 8.10 intrepid Not in release
8.04 LTS hardy Not in release
7.10 gutsy
Not affected
6.06 LTS dapper Not in release