TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2012-0217

N/A

Beschreibung

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht6/12/2012
Zuletzt geandert4/29/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

citrix:xenserverfreebsd:freebsdillumos:illumosjoyent:smartosmicrosoft:windows_7microsoft:windows_server_2003microsoft:windows_server_2008microsoft:windows_xpnetbsd:netbsdsun:sunosxen:xen

Schwachen (CWE)

CWE-119

Referenzen

http://secunia.com/advisories/55082(af854a3a-2127-422b-91ae-364da2661108)
http://security.gentoo.org/glsa/glsa-201309-24.xml(af854a3a-2127-422b-91ae-364da2661108)
http://smartos.org/2012/06/15/smartos-news-3/(af854a3a-2127-422b-91ae-364da2661108)
http://support.citrix.com/article/CTX133161(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2501(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2012/dsa-2508(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/649219(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA12-164A.html(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=813428(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/28718/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/46508/(af854a3a-2127-422b-91ae-364da2661108)
https://www.illumos.org/issues/2873(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.