Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 287936 (CVE-2009-3525) - app-emulation/xen pyGrub missing password option support (CVE-2009-3525)
Summary: app-emulation/xen pyGrub missing password option support (CVE-2009-3525)
Status: RESOLVED FIXED
Alias: CVE-2009-3525
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-10-06 18:25 UTC by Alex Legler (RETIRED)
Modified: 2009-11-06 14:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-10-06 18:25:30 UTC
CVE-2009-3525 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3525):
  The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not
  support the password option in grub.conf for para-virtualized guests,
  which allows attackers with access to the para-virtualized guest
  console to boot the guest or modify the guest's kernel boot
  parameters without providing the expected password.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-10-06 18:28:04 UTC
Please remove the aforementioned versions.
Comment 2 Patrick Lauer gentoo-dev 2009-10-27 22:15:08 UTC
+  27 Oct 2009; Patrick Lauer <patrick@gentoo.org> -xen-3.3.0.ebuild,
+  -xen-3.3.1.ebuild, -xen-3.3.1-r1.ebuild:
+  Removing old versions for #287936

no 3.0 version around, everything else unaffected.
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2009-11-06 14:39:12 UTC
Closing noglsa then.