1.9
CVSSv2

CVE-2013-4368

Published: 17/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and previous versions, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.2.3

xen xen 4.2.2

xen xen 4.2.1

xen xen 4.1.0

xen xen 4.0.4

xen xen 3.4.2

xen xen 3.4.1

xen xen 3.2.1

xen xen 3.2.0

xen xen 3.1.4

xen xen 4.1.4

xen xen 4.1.3

xen xen 4.0.1

xen xen 4.0.0

xen xen 3.3.1

xen xen 3.3.0

xen xen 3.0.3

xen xen 3.0.2

xen xen 4.1.6.1

xen xen

xen xen 4.1.2

xen xen 4.1.1

xen xen 3.4.4

xen xen 3.4.3

xen xen 3.2.3

xen xen 3.2.2

xen xen 4.2.0

xen xen 4.1.5

xen xen 4.0.3

xen xen 4.0.2

xen xen 3.4.0

xen xen 3.3.2

xen xen 3.1.3

xen xen 3.0.4

Vendor Advisories

Synopsis Moderate: kernel security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated kernel packages that fix multiple security issues and one bug arenow available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impa ...
Multiple security issues have been discovered in the Xen virtualisation solution which may result in information leaks or denial of service For the stable distribution (wheezy), these problems have been fixed in version 414-3+deb7u2 For the unstable distribution (sid), these problems will be fixed soon We recommend that you upgrade your xen pa ...
The outs instruction emulation in Xen 31x, 42x, 43x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register ...