header-logo
Suggest Exploit
vendor:
Xen
by:
SecurityFocus
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Xen
Affected Version From: Xen 3.3
Affected Version To: Xen 3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:xen:xen
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Xen Configuration Information Disclosure Vulnerability

Xen is prone to a vulnerability that results in configuration information being stored in a location that is writable by guest domains. An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.

Mitigation:

Users should apply the appropriate updates to mitigate this issue.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/31499/info

Xen is prone to a vulnerability that results in configuration information being stored in a location that is writable by guest domains.

UPDATE (December 19, 2008): The initial proposed patches did not resolve this issue.

Xen 3.3 is vulnerable; other versions may also be affected. 

#yum install xen
# xenstore-write /local/domain/GUEST-DOMID/console/tty /i/am/the/evil/guest