CVE-2015-3340
Severity
2.9LOW
EPSS
0.6%
top 29.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 28
Latest updateMay 14
Description
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
CVSS vector
AV:A/AC:M/C:P/I:N/A:NExploitability: 5.5 | Impact: 2.9
Affected Packages8 packages
Also affects: Debian Linux 7.0, 8.0, Fedora 20, 21, 22