Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3340


Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.


Published

2015-04-28T14:59:02.560

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.9 (LOW)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

5.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System xen xen 4.2.0 Yes
Operating System xen xen 4.2.1 Yes
Operating System xen xen 4.2.2 Yes
Operating System xen xen 4.2.3 Yes
Operating System xen xen 4.2.4 Yes
Operating System xen xen 4.2.5 Yes
Operating System xen xen 4.3.0 Yes
Operating System xen xen 4.3.1 Yes
Operating System xen xen 4.3.2 Yes
Operating System xen xen 4.3.3 Yes
Operating System xen xen 4.3.4 Yes
Operating System xen xen 4.4.0 Yes
Operating System xen xen 4.4.1 Yes
Operating System xen xen 4.4.2 Yes
Operating System xen xen 4.5.0 Yes
Application suse suse_linux_enterprise_software_development_kit 11.0 Yes
Operating System suse suse_linux_enterprise_desktop 11.0 Yes
Operating System suse suse_linux_enterprise_server 11.0 Yes
Operating System fedoraproject fedora 20 Yes
Operating System fedoraproject fedora 21 Yes
Operating System fedoraproject fedora 22 Yes
Operating System debian debian_linux 7.0 Yes
Operating System debian debian_linux 8.0 Yes
Operating System opensuse opensuse 13.1 Yes
Operating System suse linux_enterprise_desktop 12 Yes
Operating System suse linux_enterprise_software_development_kit 12 Yes
Operating System suse suse_linux_enterprise_server 12 Yes

References