Back to search
CVE-2013-4368
Published: Oct 17, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
GLSA-201407-03
vendor-advisory
x_refsource_GENTOO
xen-cve20134368-info-disc(87799)
vdb-entry
x_refsource_XF
RHSA-2013:1449
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
DSA-3006
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:1636
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now