VDB

DEBIAN-CVE-2018-10472

DEBIAN-CVE-2018-10472 PUBLISHED CVSS 5.599999904632568 MEDIUM

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

Risk Scores

CVSS v3.0
5.599999904632568
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14xen0, 0, 0
Debian:12xen0, 0, 0
Debian:11xen0, 0, 0
Debian:13xen0, 0, 0

Timeline

  • Apr 27, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›