[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Thu, 1 Oct 2009 13:09:58 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security <oss-security@...ts.openwall.com>,
oss-security <oss-security@...ts.openwall.com>
cc: "Steven M. Christey" <coley@...us.mitre.org>,
Michal Novotny <minovotn@...hat.com>
Subject: Re: CVE Request -- Xen -- PyGrub
On Fri, 25 Sep 2009, Jan Lieskovsky wrote:
> Xen's PyGrub, when grub.conf was configured with password protection,
> did not check for the password at host boot time. An attacker, with physical
> access to the host, could use this flaw to change the OS booting configuration.
Use CVE-2009-3525, to be filled in later.
- Steve
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ