CVE-2015-3340

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.9 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
xenxen
4.2.0
xenxen
4.2.1
xenxen
4.2.2
xenxen
4.2.3
xenxen
4.2.4
xenxen
4.2.5
xenxen
4.3.0
xenxen
4.3.1
xenxen
4.3.2
xenxen
4.3.3
xenxen
4.3.4
xenxen
4.4.0
xenxen
4.4.1
xenxen
4.4.2
xenxen
4.5.0
susesuse_linux_enterprise_software_development_kit
11.0:sp3
susesuse_linux_enterprise_desktop
11.0:sp3
susesuse_linux_enterprise_server
11.0:sp3
debiandebian_linux
7.0
debiandebian_linux
8.0
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xen
bullseye
4.14.6-1
fixed
bullseye (security)
4.14.5+94-ge49571868d-1
fixed
bookworm
4.17.3+10-g091466ba55-1~deb12u1
fixed
sid
4.17.3+36-g54dacb5c02-1
fixed
trixie
4.17.3+36-g54dacb5c02-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xen
wily
not-affected
vivid
Fixed 4.5.0-1ubuntu4.1
released
utopic
Fixed 4.4.1-0ubuntu0.14.10.6
released
trusty
Fixed 4.4.1-0ubuntu0.14.04.6
released
precise
Fixed 4.1.6.1-0ubuntu0.12.04.6
released
lucid
dne
xen-3.3
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
dne
lucid
not-affected