>> Xen Para-Virtual Frame Buffer Local Buffer Overflow Vulnerability
Title : Xen Para-Virtual Frame Buffer Local Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1900 CVE ID : CVE-2008-1943 CWE ID : CWE-119
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-06-23
Technical Description
A vulnerability has been identified in Xen, which could be exploited by local attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the PVFB (Para-Virtual Frame Buffer) backend when processing descriptions, which could be exploited by malicious users to crash an affected application or potentially execute arbitrary code in dom0.