=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2008/VULN538
_____________________________________________________________________

DATE                      : 20/11/2008

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running XenServer.

======================================================================
http://support.citrix.com/article/CTX118766
______________________________________________________________________

Vulnerability in XenServer could result in privilege escalation and
arbitrary code execution
Document ID: CTX118766   /   Created On: 17 nov. 2008   /
Updated On: 17 nov. 2008

Severity: Medium

Description of Problem

A vulnerabilitly has been identified in Citrix XenServer that could
result in attackers escaping a guest domain and potentially executing
arbitrary code in in the control domain.

This vulnerability has been assigned the following CVE number:

      • CVE-2007-5497

This vulnerability is present in all versions of XenServer up to and
including 4.1.0.

Mitigating Factors

In order to exploit this vulnerability the user needs write access to
an Ext2/Ext3 partition which is used by XenServer to boot a guest
domain running Linux.

What Customers Should Do

A hotfix has been released to address this issue. Citrix recommends
that affected customers install this hotfix, which can be downloaded
from the following locations:

XenServer 4.1.0:

http://support.citrix.com/article/CTX119081

XenServer 4.0.1:

http://support.citrix.com/article/CTX119080

What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential
security issue. This article is also available from the Citrix Knowledge
Center at http://support.citrix.com/.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix
Technical Support. Contact details for Citrix Technical Support are
available at http://www.citrix.com/site/ss/supportContacts.asp.

Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and considers
any and all potential vulnerabilities seriously. If you would like to report
a security issue to Citrix, please compose an e-mail to secure@citrix.com
stating the exact version of the product in which the vulnerability was found
and the steps needed to reproduce the vulnerability.

This document applies to:

    * XenServer 4.0
    * XenServer 4.1
    * XenServer 5.0


======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================
