5.5

CVE-2020-11740

An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xen ≫ Xen Version >= 3.2.0 <= 4.13.0
Xen ≫ Xen Version 4.13.0 Update rc1
Xen ≫ Xen Version 4.13.0 Update rc2
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Opensuse ≫ Leap Version 15.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.345
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5M2XRNCHOGGTJQBZQJ7DCV6ZNAKN3LE2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVTP4OYHCTRU3ONFJOFJQVNDFB25KLLG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YMAW7D2MP6RE4BFI5BZWOBBWGY3VSOFN/
https://security.gentoo.org/glsa/202005-08
Third Party Advisory
https://www.debian.org/security/2020/dsa-4723
Third Party Advisory
http://www.openwall.com/lists/oss-security/2020/04/14/1
Patch
Third Party Advisory
Mailing List
http://xenbits.xen.org/xsa/advisory-313.html
Patch
Vendor Advisory
https://xenbits.xen.org/xsa/advisory-313.html
Patch
Vendor Advisory