vulnerability
FreeBSD: VID-59f79c99-ba4d-11e6-ae1b-002590263bf5 (CVE-2016-9380): xen-tools -- delimiter injection vulnerabilities in pygrub
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | Dec 4, 2016 | Dec 4, 2016 | Dec 10, 2025 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Dec 4, 2016
Added
Dec 4, 2016
Modified
Dec 10, 2025
Description
The Xen Project reports: pygrub, the boot loader emulator, fails to quote (or sanity check) its results when reporting them to its caller. A malicious guest administrator can obtain the contents of sensitive host files (an information leak). Additionally, a malicious guest administrator can cause files on the host to be removed, causing a denial of service. In some unusual host configurations, ability to remove certain files may be usable for privilege escalation.
Solution
freebsd-upgrade-package-xen-tools
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.