Описание
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
It was found that the libvirt daemon, when using RBD (RADOS Block Device), leaked private credentials to the process list. A local attacker could use this flaw to perform certain privileged operations within the cluster.
Отчет
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates of Enterprise Linux 6. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | libvirt | Will not fix | ||
Red Hat Enterprise Linux 6 | libvirt | Will not fix | ||
Red Hat Storage 2.1 | libvirt | Not affected | ||
Red Hat Enterprise Linux 7 | libvirt | Fixed | RHSA-2016:2577 | 03.11.2016 |
Red Hat Gluster Storage 3.1 for RHEL 7 | libvirt | Fixed | RHSA-2016:2577 | 03.11.2016 |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | libvirt | Fixed | RHSA-2016:2577 | 03.11.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
2.1 Low
CVSS2
Связанные уязвимости
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
libvirt before 2.2 includes Ceph credentials on the qemu command line ...
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
ELSA-2016-2577: libvirt security, bug fix, and enhancement update (MODERATE)
EPSS
3.3 Low
CVSS3
2.1 Low
CVSS2