CVE-2008-1952

NameCVE-2008-1952
DescriptionThe backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs487095

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xen-3source(unstable)3.2.1-2medium487095
xen-unstablesource(unstable)(not affected)

Notes

- xen-unstable <not-affected> (Vulnerable code not present, introduced in changeset 17630)
vulnerable code no longer present as of xen 3.4 (xenfb.c has been removed)

Search for package or bug name: Reporting problems