CVE

Id
96200  
CVE No.
CVE-2016-9380  
Status
Candidate  
Description
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.  
Phase
Assigned (20161117)  
Votes
None (candidate not yet proposed)  
Comments