CVE-2015-3340

Severity
2.9LOW
EPSS
0.6%
top 29.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28
Latest updateMay 14

Description

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

CVSS vector

AV:A/AC:M/C:P/I:N/A:NExploitability: 5.5 | Impact: 2.9

Affected Packages8 packages

Debianxen< 4.6.0-1+3
NVDxen/xen15 versions+14

Also affects: Debian Linux 7.0, 8.0, Fedora 20, 21, 22

Patches

🔴Vulnerability Details

3
GHSA
GHSA-32p3-vxg7-c4m2: Xen 42022-05-14
OSV
CVE-2015-3340: Xen 42015-04-28
CVEList
CVE-2015-3340: Xen 42015-04-28

📋Vendor Advisories

2
Red Hat
xen: information leak through XEN_DOMCTL_gettscinfo (xsa132)2015-04-20
Debian
CVE-2015-3340: xen - Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain...2015

💬Community

2
Bugzilla
CVE-2015-3340 xen: information leak through XEN_DOMCTL_gettscinfo (xsa132)2015-04-21
Bugzilla
CVE-2015-3340 xen: information leak through XEN_DOMCTL_gettscinfo (xsa132) [fedora-all]2015-04-21