CVE-2013-4368: Infoleak
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4368?
CVE-2013-4368 has a moderate severity level due to the potential for local 64-bit PV guests to access sensitive hypervisor stack content.
How do I fix CVE-2013-4368?
To mitigate CVE-2013-4368, upgrade to a version of Xen later than 4.3.0 or apply relevant patches provided by the Xen project.
What versions of Xen are affected by CVE-2013-4368?
CVE-2013-4368 affects Xen versions 3.1.x, 3.2.x, 3.3.x, 3.4.x, 4.0.x, 4.1.x, and 4.2.x up to the specified limits.
Can CVE-2013-4368 be exploited remotely?
No, CVE-2013-4368 is considered a local vulnerability, meaning it requires local access to the affected system to be exploited.
What impact does CVE-2013-4368 have on system security?
The impact of CVE-2013-4368 is that it may allow unauthorized access to sensitive hypervisor data, which could lead to data leakage.