CVE-2016-9384: Infoleak
Published Feb 22, 2017
·Updated
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
Affected Software
2 affected components
XEN Xen=4.7.0
XEN Xen=4.7.1
Remediation
Patch Available
Patch Available
Event History
Feb 22, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9384?
CVE-2016-9384 has a moderate severity level, as it allows local guest OS users to access sensitive host information.
2
How does CVE-2016-9384 exploit work?
CVE-2016-9384 exploits a vulnerability in Xen 4.7 that allows malicious guest OS users to load a 32-bit ELF symbol table.
3
Which versions of Xen are affected by CVE-2016-9384?
CVE-2016-9384 affects Xen versions 4.7.0 and 4.7.1.
4
How do I fix CVE-2016-9384?
To fix CVE-2016-9384, users should upgrade to a patched version of Xen that addresses this vulnerability.
5
What type of information can be disclosed due to CVE-2016-9384?
CVE-2016-9384 can lead to the disclosure of sensitive host information to local guest OS users.