LOW · 2.9

CVE-2015-3340

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_ge...

Vulnerability Description

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

CVSS Score

2.9

LOW

AV:A/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XenXen4.2.0
SuseSuse Linux Enterprise Software Development Kit11.0
SuseSuse Linux Enterprise Desktop11.0
SuseSuse Linux Enterprise Server11.0
FedoraprojectFedora20
DebianDebian Linux7.0
OpensuseOpensuse13.1
SuseLinux Enterprise Desktop12
SuseLinux Enterprise Software Development Kit12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3340?

CVE-2015-3340 is a vulnerability with a CVSS score of 2.9 (LOW). Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_ge...

How severe is CVE-2015-3340?

CVE-2015-3340 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3340?

Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen, Suse Suse Linux Enterprise Software Development Kit, Suse Suse Linux Enterprise Desktop, Suse Suse Linux Enterprise Server, Fedoraproject Fedora.