Vulnerability Description
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | <= 4.0.1 |
Related Weaknesses (CWE)
References
- http://downloads.avaya.com/css/P8/documents/100145416
- http://rhn.redhat.com/errata/RHSA-2011-0833.html
- http://wiki.xen.org/wiki/Security_Announcements#XSA-1_Host_crash_due_to_failure_PatchVendor Advisory
- http://downloads.avaya.com/css/P8/documents/100145416
- http://rhn.redhat.com/errata/RHSA-2011-0833.html
- http://wiki.xen.org/wiki/Security_Announcements#XSA-1_Host_crash_due_to_failure_PatchVendor Advisory
FAQ
What is CVE-2011-1166?
CVE-2011-1166 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
How severe is CVE-2011-1166?
CVE-2011-1166 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1166?
Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen.