Total vulnerabilities in the database
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
Software | From | Fixed in |
---|---|---|
xen / xen | - | - |
citrix / xenserver | 7.0 | 7.0.x |
citrix / xenserver | 6.5 | 6.5.x |
citrix / xenserver | 6.0.2 | 6.0.2.x |
citrix / xenserver | 6.2.0 | 6.2.0.x |