CVE-2015-2044: Infoleak
Published Mar 12, 2015
·Updated
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Affected Software
34 affected components
XEN Xen=3.2.0
XEN Xen=3.2.1
XEN Xen=3.2.2
XEN Xen=3.2.3
XEN Xen=3.3.0
XEN Xen=3.3.1
XEN Xen=3.3.2
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
XEN Xen=4.4.1
XEN Xen=4.5.0
Event History
Mar 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2044?
CVE-2015-2044 has a severity rating that indicates it could allow local HVM guest users to obtain sensitive information.
2
How do I fix CVE-2015-2044?
To fix CVE-2015-2044, update your Xen installation to a version that includes the relevant security patches.
3
Which versions of Xen are affected by CVE-2015-2044?
CVE-2015-2044 affects Xen versions from 3.2.x through 4.5.x.
4
Can CVE-2015-2044 be exploited remotely?
CVE-2015-2044 requires local access to the HVM guest environment to be exploited.
5
What type of vulnerability is CVE-2015-2044?
CVE-2015-2044 is a local information disclosure vulnerability impacting unspecified X86 devices in Xen.