The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/55082 | third party advisory |
http://www.openwall.com/lists/oss-security/2013/06/26/4 | mailing list |
http://security.gentoo.org/glsa/glsa-201309-24.xml | vendor advisory |
http://www.openwall.com/lists/oss-security/2013/06/25/1 | mailing list |
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html | vendor advisory |
http://www.debian.org/security/2014/dsa-3006 | vendor advisory |