PT-2013-4973 · Xen+1 · Xen+1

Jan Beulich

·

Published

2013-10-01

·

Updated

2024-06-15

·

CVE-2013-4361

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.3.x
Description The issue concerns the fbld instruction emulation, which does not use the correct variable for the source effective address. This allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Recommendations For Xen versions 3.3.x through 4.3.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4361
DSA-3006-1
OPENSUSE-SU-2024:10196-1

Affected Products

Suse
Xen