CVE-2017-7995
3.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.0 / Impact: 1.4
Source: NVD
Description
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
Affected (6)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 sp3 | |
| Version 11.0 sp3 | |
| Version 2.1 | |
| Version 2.1 | |
| Version 5 |
References (6)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry
Timeline
No history available yet.