PT-2013-4973 · Xen+1 · Xen+1
Jan Beulich
·
Published
2013-10-01
·
Updated
2024-06-15
·
CVE-2013-4361
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.3.x through 4.3.x
Description
The issue concerns the fbld instruction emulation, which does not use the correct variable for the source effective address. This allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Recommendations
For Xen versions 3.3.x through 4.3.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen