CVE-2013-4368 describes an information disclosure vulnerability in Xen versions 3.1.x, 4.2.x, and 4.3.x. A flaw in the emulation of the "outs" instruction, specifically when using FS: or GS: segment overrides, leads to the use of an uninitialized variable as a segment base. This allows local 64-bit PV guests to potentially leak sensitive hypervisor stack content. The vulnerability has a low CVSS score of 1.9, indicating a low severity. It requires local access and medium attack complexity (AV:L/AC:M), with the primary impact being confidentiality (C:P) due to information disclosure. There is no impact on integrity or availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
3.0.2CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.2:*:*:*:*:*:*:* | ||
3.0.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.3:*:*:*:*:*:*:* | ||
3.0.4CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.4:*:*:*:*:*:*:* | ||
3.1.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.