CVE-2013-4368 PUBLISHED CVSS 1.899999976158142 LOW

The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.

EPSS 0.09% · 26.3th percentile

Risk Scores

CVSS v2.0
1.899999976158142
EPSS Score
0.09%
26.3th percentile

Affected Products

VendorProductVersions
xenxen3.2.0, 0, 3.0.2
n/an/an/a

Timeline

References

Open in Interactive Console →