CVE-2013-4361: Infoleak
Published Oct 1, 2013
·Updated
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Affected Software
23 affected components
XEN Xen=3.3.0
XEN Xen=3.3.1
XEN Xen=3.3.2
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.3.0
Event History
Oct 1, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4361?
CVE-2013-4361 has a medium severity rating as it allows local HVM guests to access hypervisor stack information.
2
How do I fix CVE-2013-4361?
To fix CVE-2013-4361, you should upgrade your Xen hypervisor to a version that addresses this vulnerability.
3
Which versions of Xen are affected by CVE-2013-4361?
CVE-2013-4361 affects Xen versions from 3.3.x through 4.3.x.
4
Is CVE-2013-4361 an issue for HVM guests?
Yes, CVE-2013-4361 specifically affects local HVM guests in the Xen hypervisor.
5
What consequences may arise from CVE-2013-4361?
The consequence of CVE-2013-4361 is that an attacker could gain sensitive information from the hypervisor's stack through local exploitation.