Script Error Opens up Security Hole in Xen 3.0.3
A Red Hat update has just been released to close various vulnerabilities in the Xen virtualization solution, one of which was caused by an error in a Python script.
The vulnerability, which has been assigned the CVE number CVE-2007-4993, is in the tools/pygrub/src/GrubConf.py script and was discovered by Joris van Rantwijk. Security researchers Secunia classify the error as moderately critical. It can be exploited by manipulating the Grub bootloader. A successful attacker would have the ability to execute arbitrary commands in domain 0 which has hardware access.
Tavis Ormandy found another bug (CVE-2007-1320) which triggers a heap overflow on video-to-video copy actions in the Cirrus VGA extension. An administrative user in a guest domain might be able to exploit this to execute malicious code outside their own domain.
The third vulnerability, (CVE-2007-1321), which was also discovered by Ormandy, triggers a heap overflow in the Xen NE2000 network driver. If the driver is used, a local administrator has the ability to execute arbitrary malicious code in other domains. The developers point out that Xen does not use the buggy driver by default.
Red Hat has released an update to close all three security holes. Version 3.0.3 of Xen is affected. It is unclear whether other versions have the bugs. Xen users are advised to update their installations as quickly as possible. Red Hat is currently the only source for the updates.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
So Long Neofetch and Thanks for the Info
Today is a day that every Linux user who enjoys bragging about their system(s) will mourn, as Neofetch has come to an end.
-
Ubuntu 24.04 Comes with a “Flaw"
If you're thinking you might want to upgrade from your current Ubuntu release to the latest, there's something you might want to consider before doing so.
-
Canonical Releases Ubuntu 24.04
After a brief pause because of the XZ vulnerability, Ubuntu 24.04 is now available for install.
-
Linux Servers Targeted by Akira Ransomware
A group of bad actors who have already extorted $42 million have their sights set on the Linux platform.
-
TUXEDO Computers Unveils Linux Laptop Featuring AMD Ryzen CPU
This latest release is the first laptop to include the new CPU from Ryzen and Linux preinstalled.
-
XZ Gets the All-Clear
The back door xz vulnerability has been officially reverted for Fedora 40 and versions 38 and 39 were never affected.
-
Canonical Collaborates with Qualcomm on New Venture
This new joint effort is geared toward bringing Ubuntu and Ubuntu Core to Qualcomm-powered devices.
-
Kodi 21.0 Open-Source Entertainment Hub Released
After a year of development, the award-winning Kodi cross-platform, media center software is now available with many new additions and improvements.
-
Linux Usage Increases in Two Key Areas
If market share is your thing, you'll be happy to know that Linux is on the rise in two areas that, if they keep climbing, could have serious meaning for Linux's future.
-
Vulnerability Discovered in xz Libraries
An urgent alert for Fedora 40 has been posted and users should pay attention.