CVE

Id
40960  
CVE No.
CVE-2009-3525  
Status
Candidate  
Description
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest"s kernel boot parameters without providing the expected password.  
Phase
Assigned (20091001)  
Votes
None (candidate not yet proposed)  
Comments