CVE-2015-3340

EUVD-2015-3385
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
xenxen
4.2.0
xenxen
4.2.1
xenxen
4.2.2
xenxen
4.2.3
xenxen
4.2.4
xenxen
4.2.5
xenxen
4.3.0
xenxen
4.3.1
xenxen
4.3.2
xenxen
4.3.3
xenxen
4.3.4
xenxen
4.4.0
xenxen
4.4.1
xenxen
4.4.2
xenxen
4.5.0
susesuse_linux_enterprise_software_development_kit
11.0:sp3
susesuse_linux_enterprise_desktop
11.0:sp3
susesuse_linux_enterprise_server
11.0:sp3
debiandebian_linux
7.0
debiandebian_linux
8.0
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xen
bookworm
4.17.3+10-g091466ba55-1~deb12u1
fixed
bullseye
4.14.6-1
fixed
bullseye (security)
4.14.5+94-ge49571868d-1
fixed
sid
4.17.3+36-g54dacb5c02-1
fixed
trixie
4.17.3+36-g54dacb5c02-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xen
lucid
dne
precise
Fixed 4.1.6.1-0ubuntu0.12.04.6
released
trusty
Fixed 4.4.1-0ubuntu0.14.04.6
released
utopic
Fixed 4.4.1-0ubuntu0.14.10.6
released
vivid
Fixed 4.5.0-1ubuntu4.1
released
wily
not-affected
xen-3.3
lucid
not-affected
precise
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne