CVE Database
/

CVE-2013-4368

Back to search

CVE-2013-4368

Published: Oct 17, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
GLSA-201407-03
vendor-advisory
x_refsource_GENTOO
xen-cve20134368-info-disc(87799)
vdb-entry
x_refsource_XF
RHSA-2013:1449
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
DSA-3006
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:1636
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now