Secunia
|
|

CVE Reference: CVE-2012-0217 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2012-0217 |
|
|
Description: The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier. |
|
|
CVE Status: Candidate |
|
|
References: OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15596 NETBSD http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2012-003.txt.asc MS http://technet.microsoft.com/security/bulletin/MS12-042 MLIST http://lists.xen.org/archives/html/xen-devel/2012-06/msg01072.html http://lists.xen.org/archives/html/xen-announce/2012-06/msg00001.html FREEBSD http://security.freebsd.org/advisories/FreeBSD-SA-12:04.sysret.asc DEBIAN http://www.debian.org/security/2012/dsa-2501 http://www.debian.org/security/2012/dsa-2508 CONFIRM http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/ http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html http://support.citrix.com/article/CTX133161 http://wiki.smartos.org/display/DOC/SmartOS+Change+Log#SmartOSChangeLog-June14%2C2012 http://smartos.org/2012/06/15/smartos-news-3/ http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/ CERT-VN 649219 CERT http://www.us-cert.gov/cas/techalerts/TA12-164A.html |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |