2024-12-08 03:06:42 +00:00

147 lines
4.1 KiB
JSON

{
"id": "CVE-2017-10922",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-07-05T01:29:00.893",
"lastModified": "2024-11-21T03:06:45.590",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3."
},
{
"lang": "es",
"value": "La caracter\u00edstica de tabla grant en Xen, hasta las versiones 4.8.x, gestiona de manera incorrecta referencias grant de la regi\u00f3n MMIO, lo que permite que los usuarios invitados de sistema operativo provoquen una denegaci\u00f3n de servicio (p\u00e9rdida de trazabilidad de grant, tambi\u00e9n conocido como XSA-224, fallo 3."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.8.1",
"matchCriteriaId": "7494A471-EEFC-44F4-96B1-FDBA3B780313"
}
]
}
]
}
],
"references": [
{
"url": "http://www.debian.org/security/2017/dsa-3969",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id/1038734",
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201708-03",
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201710-17",
"source": "cve@mitre.org"
},
{
"url": "https://xenbits.xen.org/xsa/advisory-224.html",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.debian.org/security/2017/dsa-3969",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1038734",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201708-03",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201710-17",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://xenbits.xen.org/xsa/advisory-224.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}