CVE-2016-9380: Input Validation
Published Jan 23, 2017
·Updated
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
Affected Software
5 affected components
XEN Xen
Citrix XenServer=6.0.2
Citrix XenServer=6.2.0
Citrix XenServer=6.5
Citrix XenServer=7.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9380?
CVE-2016-9380 is rated as a medium severity vulnerability.
2
How do I fix CVE-2016-9380?
To fix CVE-2016-9380, apply the recommended patches provided by the Xen Project or Citrix.
3
Which versions of Xen are affected by CVE-2016-9380?
CVE-2016-9380 affects several versions of Xen, including all versions prior to the security patches released for this vulnerability.
4
Can CVE-2016-9380 be exploited remotely?
CVE-2016-9380 requires local access to the affected system, so it cannot be exploited remotely.
5
What types of attacks can be performed using CVE-2016-9380?
Using CVE-2016-9380, an attacker could read or delete arbitrary files on the host via crafted bootloader configuration files.