The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1...
Vulnerability Description
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-3525
Credits & Attribution
No credits recorded in the NVD database.
References
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9466
- http://www.openwall.com/lists/oss-security/2009/09/25/1
- http://secunia.com/advisories/36908
- https://bugzilla.redhat.com/show_bug.cgi?id=525740#c0
- http://www.redhat.com/support/errata/RHSA-2009-1472.html
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
- http://www.securityfocus.com/bid/36523
- http://www.securitytracker.com/id?1022950
- https://bugzilla.redhat.com/show_bug.cgi?id=525740
- http://xenbits.xensource.com/xen-unstable.hg?rev/8f783adc0ee3
More from xen
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.