CVE-2015-3340: Infoleak
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XENDOMCTLgettscinfo or (2) XENSYSCTLgetdomaininfolist request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3340?
The severity of CVE-2015-3340 is classified as high due to its potential to expose sensitive memory information to unauthorized remote service domains.
How do I fix CVE-2015-3340?
To fix CVE-2015-3340, update your Xen installation to the latest version that addresses this vulnerability.
Which versions of Xen are affected by CVE-2015-3340?
Versions of Xen affected by CVE-2015-3340 include 4.2.x through 4.5.x, specifically versions 4.2.0 to 4.5.0.
What impact does CVE-2015-3340 have on systems?
CVE-2015-3340 can lead to unauthorized access to sensitive information stored in memory, impacting the confidentiality of virtualized environments.
Is CVE-2015-3340 a remote code execution vulnerability?
No, CVE-2015-3340 is not a remote code execution vulnerability; it allows information disclosure from memory instead.