First published: Wed Feb 22 2017(Updated: )
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.7.0 | |
Xen xen-unstable | =4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9384 has a moderate severity level, as it allows local guest OS users to access sensitive host information.
CVE-2016-9384 exploits a vulnerability in Xen 4.7 that allows malicious guest OS users to load a 32-bit ELF symbol table.
CVE-2016-9384 affects Xen versions 4.7.0 and 4.7.1.
To fix CVE-2016-9384, users should upgrade to a patched version of Xen that addresses this vulnerability.
CVE-2016-9384 can lead to the disclosure of sensitive host information to local guest OS users.