ubuntu · CVE-2008-3687

Quick triage

Priority: low Published: 2008-08-14 22:41:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2008-3687 low priority: Ubuntu including 4 source packages (xen, xen-3.0, xen-3.1, xen-3.2), 20 status rows across 5 suites (dapper, feisty, gutsy, hardy, upstream): DNE 11, not-affected 5, needs-triage 4.

Description:

Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.

cvelogic Threat Intelligence