LWN.net Logo

xen: privilege escalation

Package(s):xen CVE #(s):CVE-2007-4993
Created:October 9, 2007 Updated:November 2, 2007
Description: pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.
Alerts:
Fedora FEDORA-2007-2708 2007-11-01
Mandriva MDKSA-2007:203 2007-11-01
Ubuntu USN-527-1 2007-10-05
rPath rPSA-2007-0210-1 2007-10-08

(Log in to post comments)

xen: privilege escalation

Posted Oct 13, 2007 17:46 UTC (Sat) by kreutzm (guest, #4700) [Link]

This is fixed in Debian by DSA 1384.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds