|
|
| |
|
| |
xen: guest privilege escalation
| Package(s): | xen |
CVE #(s): | CVE-2009-3525
|
| Created: | October 2, 2009 |
Updated: | May 25, 2010 |
| Description: |
From the Red Hat advisory:
The pyGrub boot loader did not honor the "password" option in the grub.conf
file for para-virtualized guests. Users with access to a guest's console
could use this flaw to bypass intended access restrictions and boot the
guest with arbitrary kernel boot options, allowing them to get root
privileges in the guest's operating system. With this update, pyGrub
correctly honors the "password" option in grub.conf for para-virtualized
guests. |
| Alerts: |
|
( Log in to post comments)
|
|
|