CVE-2013-4368 — Sensitive Information Exposure in XEN
Severity
1.9LOWNVD
EPSS
0.1%
top 73.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17
Latest updateMay 17
Description
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.
CVSS vector
AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
8Debian▶
CVE-2013-4368: xen - The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when usi...↗2013