Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
BID:31499
Info
Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
| Bugtraq ID: | 31499 |
| Class: | Design Error |
| CVE: |
CVE-2008-4405 CVE-2008-5716 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2008 12:00AM |
| Updated: | Sep 15 2009 05:51PM |
| Credit: | Pascal Bouchareine |
| Vulnerable: |
XenSource Xen 3.3 S.u.S.E. openSUSE 11.0 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 |
| Not Vulnerable: | |
Discussion
Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
Xen is prone to a vulnerability that results in configuration information being stored in a location that is writable by guest domains.
UPDATE (December 19, 2008): The initial proposed patches did not resolve this issue.
Xen 3.3 is vulnerable; other versions may also be affected.
Xen is prone to a vulnerability that results in configuration information being stored in a location that is writable by guest domains.
UPDATE (December 19, 2008): The initial proposed patches did not resolve this issue.
Xen 3.3 is vulnerable; other versions may also be affected.
Exploit / POC
Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
An attacker may exploit this issue using commonly available tools.
The following example is available:
#yum install xen
# xenstore-write /local/domain/GUEST-DOMID/console/tty /i/am/the/evil/guest
An attacker may exploit this issue using commonly available tools.
The following example is available:
#yum install xen
# xenstore-write /local/domain/GUEST-DOMID/console/tty /i/am/the/evil/guest
Solution / Fix
Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
-
Mandriva xen-3.0.1-3.2.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva xen-3.0.1-3.2.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Xen XenStore Domain Configuration Data Unsafe Storage Vulnerability
References:
References:
- libvirt/virsh access unsafe data from xenstored ( Daniel Berrange)
- [Xen-devel] [PATCH] [Xend] Move some backend configuration (XenSource)
- [Xen-devel] PATCH: Actually make /local/domain/$DOMID readonly to the guest (Daniel P. Berrange)
- Xen Project Homepage (Xen Project)