CVE-2020-29485

Source
https://cve.org/CVERecord?id=CVE-2020-29485
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29485.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-29485
Downstream
Published
2020-12-15T18:15:15.490Z
Modified
2026-02-14T00:47:30.208530Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XSRESETWATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.

References

Affected packages

Git / github.com/sleuthkit/sleuthkit

Affected ranges

Type
GIT
Repo
https://github.com/sleuthkit/sleuthkit
Events

Affected versions

ct-3.*
ct-3.10.0
ct-3.11.0
ct-3.12.0
ct-3.13.0
ct-3.5.0
ct-3.6.0
ct-3.8.0
ct-3.9.0
sleuthkit-4.*
sleuthkit-4.10.0
sleuthkit-4.10.1
sleuthkit-4.10.2
sleuthkit-4.11.0
sleuthkit-4.11.1
sleuthkit-4.12.0
sleuthkit-4.12.1
sleuthkit-4.14.0
sleuthkit-4.6.0
sleuthkit-4.6.1
sleuthkit-4.6.2
sleuthkit-4.6.3
sleuthkit-4.6.4
sleuthkit-4.6.5
sleuthkit-4.6.6
sleuthkit-4.6.7
sleuthkit-4.7.0
sleuthkit-4.8.0
sleuthkit-4.8.0-fixed
sleuthkit-4.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29485.json"