ZeroHour

CVE-2016-9380

CVSS 3.0
7.5 high
EPSS
<1%p36
Published
()
Modified
Description

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.

Vendors
xencitrix
Products
xen, xenserver
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.