CVE-2012-4411
EPSS 0.07%
Description
The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-0998.
How to fix CVE-2012-4411
To remediate CVE-2012-4411, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.3-2 or later
Is CVE-2012-4411 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.3-2