vulnerability

FreeBSD: VID-59f79c99-ba4d-11e6-ae1b-002590263bf5 (CVE-2016-9380): xen-tools -- delimiter injection vulnerabilities in pygrub

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Dec 4, 2016
Added
Dec 4, 2016
Modified
Dec 10, 2025

Description

The Xen Project reports: pygrub, the boot loader emulator, fails to quote (or sanity check) its results when reporting them to its caller. A malicious guest administrator can obtain the contents of sensitive host files (an information leak). Additionally, a malicious guest administrator can cause files on the host to be removed, causing a denial of service. In some unusual host configurations, ability to remove certain files may be usable for privilege escalation.

Solution

freebsd-upgrade-package-xen-tools
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.