First published: Thu Mar 12 2015(Updated: )
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =3.2.0 | |
Xen xen-unstable | =3.2.1 | |
Xen xen-unstable | =3.2.2 | |
Xen xen-unstable | =3.2.3 | |
Xen xen-unstable | =3.3.0 | |
Xen xen-unstable | =3.3.1 | |
Xen xen-unstable | =3.3.2 | |
Xen xen-unstable | =3.4.0 | |
Xen xen-unstable | =3.4.1 | |
Xen xen-unstable | =3.4.2 | |
Xen xen-unstable | =3.4.3 | |
Xen xen-unstable | =3.4.4 | |
Xen xen-unstable | =4.0.0 | |
Xen xen-unstable | =4.0.1 | |
Xen xen-unstable | =4.0.2 | |
Xen xen-unstable | =4.0.3 | |
Xen xen-unstable | =4.0.4 | |
Xen xen-unstable | =4.1.0 | |
Xen xen-unstable | =4.1.1 | |
Xen xen-unstable | =4.1.2 | |
Xen xen-unstable | =4.1.3 | |
Xen xen-unstable | =4.1.4 | |
Xen xen-unstable | =4.1.5 | |
Xen xen-unstable | =4.1.6.1 | |
Xen xen-unstable | =4.2.0 | |
Xen xen-unstable | =4.2.1 | |
Xen xen-unstable | =4.2.2 | |
Xen xen-unstable | =4.2.3 | |
Xen xen-unstable | =4.3.0 | |
Xen xen-unstable | =4.3.1 | |
Xen xen-unstable | =4.4.0 | |
Xen xen-unstable | =4.4.0-rc1 | |
Xen xen-unstable | =4.4.1 | |
Xen xen-unstable | =4.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2044 has a severity rating that indicates it could allow local HVM guest users to obtain sensitive information.
To fix CVE-2015-2044, update your Xen installation to a version that includes the relevant security patches.
CVE-2015-2044 affects Xen versions from 3.2.x through 4.5.x.
CVE-2015-2044 requires local access to the HVM guest environment to be exploited.
CVE-2015-2044 is a local information disclosure vulnerability impacting unspecified X86 devices in Xen.