Xen pygrub Local Authentication Bypass Vulnerability
BID:36523
Info
Xen pygrub Local Authentication Bypass Vulnerability
| Bugtraq ID: | 36523 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-3525 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2009 12:00AM |
| Updated: | Apr 13 2015 09:31PM |
| Credit: | Jan Lieskovsky |
| Vulnerable: |
XenSource Xen 3.3.1 XenSource Xen 3.3 XenSource Xen 3.0.3 SuSE SUSE Linux Enterprise 11 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server |
| Not Vulnerable: | |
Discussion
Xen pygrub Local Authentication Bypass Vulnerability
Xen is prone to a local authentication-bypass vulnerability.
A local attacker with physical access to an affected host can exploit this issue to bypass authentication and modify the 'grub.conf' file. This may aid in a complete compromise of the affected system.
Xen 3.0.3, 3.3.0, and 3.3.1 are affected; other versions may also be vulnerable.
Xen is prone to a local authentication-bypass vulnerability.
A local attacker with physical access to an affected host can exploit this issue to bypass authentication and modify the 'grub.conf' file. This may aid in a complete compromise of the affected system.
Xen 3.0.3, 3.3.0, and 3.3.1 are affected; other versions may also be vulnerable.
Exploit / POC
Xen pygrub Local Authentication Bypass Vulnerability
The following example is available:
xm create -c guest
press space bar to stop the grub count down
press e to edit
select the kernel line and press e
Append a "1" to the end of the kernel line and press return
press "b" to boot
The following example is available:
xm create -c guest
press space bar to stop the grub count down
press e to edit
select the kernel line and press e
Append a "1" to the end of the kernel line and press return
press "b" to boot
Solution / Fix
Xen pygrub Local Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xen pygrub Local Authentication Bypass Vulnerability
References:
References:
- Bug 525740 - Xen: PyGrub allows to edit it's configuration at boot time even w (Jan Lieskovsky)
- changeset: pygrub: Add password support (Xensource)
- changeset: pygrub: Correct pygrub return value (Xensource)
- changeset: pygrub: Fix elilo handling after password patch. (Xensource)
- changeset: pygrub: Match bare-metal GRUB behavior for passwords (Xensource)
- changeset: pygrub: trap exception when python module import fails (Xensource)
- CVE Request -- Xen -- PyGrub (Jan iankko Lieskovsky)
- Xen Project Homepage (Xen Project)