Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6434

Опубликовано: 21 янв. 2014
Источник: redhat
CVSS2: 4.3

Описание

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

Дополнительная информация

Статус:

Important
Дефект:
CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1039839rhev: remote-viewer spice tls-stripping issue

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

nvd
около 12 лет назад

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

github
больше 3 лет назад

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

4.3 Medium

CVSS2