Xen Information Disclosure Vulnerability: CVE-2017-17046
by CIRT Team
Description: An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.
Impact: Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Mitigation: Updates are available. Please see the references or vendor advisory for more information.
Reference URL’s:
- http://xenbits.xenproject.org/xsa/advisory-245.html
- http://www.securityfocus.com/bid/101067/info
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17046
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts