Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xen pygrub 脚本本地命令注入漏洞
Vulnerability Description
Xen是英国剑桥大学开发的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen的实现上存在漏洞,本地攻击者可能利用此漏洞提升自己的权限。 在启动guest域时,pygrub使用Python exec()语句处理grub.conf的不可信任数据,如果创建了特制的grub.conf文件的话,guest域中的root用户就可以在Domain-0中执行任意Python代码。 有漏洞的代码位于tools/pygrub/src/
CVSS Information
N/A
Vulnerability Type
N/A