SciLinux: CVE-2007-1320 xen SL5.x i386/x86_64
Summary
Date: Thu, 4 Oct 2007 10:38:51 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for xen on SL5.x i386/x86_64Comments: To: scientific Synopsis: Important: xen security updateCVE Names: CVE-2007-1320 CVE-2007-1321 CVE-2007-4993Detail:Joris van Rantwijk found a flaw in the Pygrub utility which is used as aboot loader for guest domains. A malicious local administrator of a guestdomain could create a carefully crafted grub.conf file which would triggerthe execution of arbitrary code outside of that domain. (CVE-2007-4993)Tavis Ormandy discovered a heap overflow flaw during video-to-video copyoperations in the Cirrus VGA extension code used in Xen. A malicious localadministrator of a guest domain could potentially trigger this flaw andexecute arbitrary code outside of the domain. (CVE-2007-1320)Tavis Ormandy discovered insufficient input validation leading to a heapoverflow in the Xen NE2000 network driver. If the driver is in use, amalicious local administrator of a guest domain could potentially triggerthis flaw and execute arbitrary code outside of the domain. Xen does notuse this driver by default. (CVE-2007-1321)SL5.x SRPMS: xen-3.0.3-25.0.4.el5.src.rpm i386: xen-3.0.3-25.0.4.el5.i386.rpm xen-devel-3.0.3-25.0.4.el5.i386.rpm xen-libs-3.0.3-25.0.4.el5.i386.rpm x86_64: xen-3.0.3-25.0.4.el5.x86_64.rpm xen-devel-3.0.3-25.0.4.el5.i386.rpm xen-devel-3.0.3-25.0.4.el5.x86_64.rpm xen-libs-3.0.3-25.0.4.el5.i386.rpm xen-libs-3.0.3-25.0.4.el5.x86_64.rpm-Connie Sieh-Troy Dawson