CVE-2013-4361

NameCVE-2013-4361
DescriptionThe fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-3006-1
NVD severitylow (attack range: local)
Debian/oldstablepackage xen is vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xen (PTS)squeeze (security), squeeze4.0.1-5.11vulnerable
wheezy4.1.4-3+deb7u3fixed
wheezy (security)4.1.4-3+deb7u4fixed
jessie, sid4.4.1-6fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xensource(unstable)4.4.0-1low
xensourcesqueeze(unfixed)end-of-life
xensourcewheezy4.1.4-3+deb7u2lowDSA-3006-1

Notes

[squeeze] - xen <end-of-life> (Unsupported in squeeze-lts)

Search for package or bug name: Reporting problems