Submitted by KeesCook on Tue, 2007-10-09 17:08
Referenced CVEs:
CVE-2007-4993
Description:
===========================================================
Ubuntu Security Notice USN-527-1 October 05, 2007
xen-3.0 vulnerability
CVE-2007-4993
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.04:
xen-utils-3.0 3.0.3-0ubuntu10.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Joris van Rantwijk discovered that the Xen host did not correctly validate
the contents of a Xen guests's grub.conf file. Xen guest root users could
exploit this to run arbitrary commands on the host when the guest system
was rebooted.


