CVE-2013-4355
EPSS 0.31%
Description
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
How to fix CVE-2013-4355
To remediate CVE-2013-4355, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.4.0-1 or later
Is CVE-2013-4355 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.0-1