CVE Vulnerabilities

CVE-2009-3525

Published: Oct 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guests kernel boot parameters without providing the expected password.

Affected Software

NameVendorStart VersionEnd Version
XenXen3.0.3 (including)3.0.3 (including)
XenXen3.3.0 (including)3.3.0 (including)
XenXen3.3.1 (including)3.3.1 (including)
Red Hat Enterprise Linux 5RedHatxen-0:3.0.3-94.el5_4.1*
XenUbuntudapper*
XenUbuntudevel*
XenUbuntuupstream*
Xen-3.1Ubuntuhardy*
Xen-3.1Ubuntuintrepid*
Xen-3.1Ubuntuupstream*
Xen-3.2Ubuntuhardy*
Xen-3.2Ubuntuupstream*
Xen-3.3Ubuntudevel*
Xen-3.3Ubuntuintrepid*
Xen-3.3Ubuntujaunty*
Xen-3.3Ubuntukarmic*
Xen-3.3Ubuntulucid*
Xen-3.3Ubuntumaverick*
Xen-3.3Ubuntunatty*
Xen-3.3Ubuntuupstream*

References