5.5 CVE-2024-45819
Enriched by CISA Patch
PVH guests have their ACPI tables constructed by the toolstack. The
construction involves building the tables in local memory, which are
then copied into guest memory. While actually used parts of the local
memory are filled in correctly, excess space that is being allocated is
left with its prior contents.
https://nvd.nist.gov/vuln/detail/CVE-2024-45819
Categories
CWE-276 : Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files. The architecture needs to access and modification attributes for files to only those users who actually require those actions. Executables installed world-writable. Home directories installed world-readable. World-writable log files allow information loss; world-readable file has cleartext passwords. World-readable directory. Windows product uses insecure permissions when installing on Solaris (genesis: port error). Insecure permissions for a shared secret key file. Overlaps cryptographic problem. Default permissions of a device allow IP spoofing.
References
af854a3a-2127-422b-91ae-364da2661108 Patch
| http://www.openwall.com/lists/oss-security/2024/11/12/1 Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/11/12/10 Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/11/12/7 Mailing List Third Party Advisory |
| http://xenbits.xen.org/xsa/advisory-464.html Patch Vendor Advisory |
security@xen.org Patch
| https://xenbits.xenproject.org/xsa/advisory-464.html Patch Vendor Advisory |
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen |
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|---|---|
| Configuration 1 | ||
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | >= 4.8.0 | |
REMEDIATION
Patch
| Url |
|---|
| http://xenbits.xen.org/xsa/advisory-464.html |
| https://xenbits.xenproject.org/xsa/advisory-464.html |
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| 1 | Accessing Functionality Not Properly Constrained by ACLs |
High |
| 127 | Directory Indexing |
Medium |
| 81 | Web Server Logs Tampering |
High |
MITRE
Techniques
| id | description |
|---|---|
| T1083 | File and Directory Discovery |
| T1574.010 | Hijack Execution Flow: ServicesFile Permissions Weakness |
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | |
Mitigations
| id | description |
|---|---|
| M1018 | Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Deny execution from user directories such as file download directories and temp directories where able. |
| © 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation. | |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
