The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guests kernel boot parameters without providing the expected password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xen | Xen | 3.0.3 (including) | 3.0.3 (including) |
Xen | Xen | 3.3.0 (including) | 3.3.0 (including) |
Xen | Xen | 3.3.1 (including) | 3.3.1 (including) |
Red Hat Enterprise Linux 5 | RedHat | xen-0:3.0.3-94.el5_4.1 | * |
Xen | Ubuntu | dapper | * |
Xen | Ubuntu | devel | * |
Xen | Ubuntu | upstream | * |
Xen-3.1 | Ubuntu | hardy | * |
Xen-3.1 | Ubuntu | intrepid | * |
Xen-3.1 | Ubuntu | upstream | * |
Xen-3.2 | Ubuntu | hardy | * |
Xen-3.2 | Ubuntu | upstream | * |
Xen-3.3 | Ubuntu | devel | * |
Xen-3.3 | Ubuntu | intrepid | * |
Xen-3.3 | Ubuntu | jaunty | * |
Xen-3.3 | Ubuntu | karmic | * |
Xen-3.3 | Ubuntu | lucid | * |
Xen-3.3 | Ubuntu | maverick | * |
Xen-3.3 | Ubuntu | natty | * |
Xen-3.3 | Ubuntu | upstream | * |