PT-2013-4969 · Citrix+2 · Xen+2

Andrew Cooper

+1

·

Published

2013-10-01

·

Updated

2024-06-15

·

CVE-2013-4355

CVSS v2.0

1.5

Low

VectorAV:L/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen versions 4.3.x and earlier
Description The issue arises from improper error handling, allowing local HVM guests to access hypervisor stack memory through various operations, including port or memory mapped I/O writes, or other unspecified address-related operations without associated memory.
Recommendations For versions 4.3.x and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4355
DSA-3006-1
OPENSUSE-SU-2024:10196-1
RHSA-2013:1790
RHSA-2013_1790

Affected Products

Red Hat
Suse
Xen