SB2016120111 - Input validation error in xen (Alpine package)
Published: December 1, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2016-9380)
The vulnerability allows a local authenticated user to read and manipulate data.
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=e719edc6313651540e9d90f5600c2ed605fa6abf
- https://git.alpinelinux.org/aports/commit/?id=606dbad6dd155ec3aebfba4513206d9bdea93b52
- https://git.alpinelinux.org/aports/commit/?id=473c36a9c87f281b12c59f519ab621ff620a7062
- https://git.alpinelinux.org/aports/commit/?id=9bd4f34be948ebfa595d57f19e164b329c94ef70
- https://git.alpinelinux.org/aports/commit/?id=ef362e4b0451d7206239a58f9ca6c6389652b7a9