Unrated severityNVD Advisory· Published Aug 14, 2008· Updated Apr 23, 2026
CVE-2008-3687
CVE-2008-3687
Description
Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.
Affected products
2- cpe:2.3:a:xen:xen_flask_module:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.nabble.com/-PATCH--XSM--FLASK--Argument-handling-bugs-in-XSM:FLASK-to18536032.htmlnvdPatch
- invisiblethingslab.com/bh08/part2.pdfnvd
- secunia.com/advisories/31561nvd
- theinvisiblethings.blogspot.com/2008/08/our-xen-0wning-trilogy-highlights.htmlnvd
- www.securityfocus.com/bid/30834nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/2426nvd
- xenbits.xensource.com/xen-3.3-testing.hgnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44608nvd
News mentions
0No linked articles in our index yet.