PT-2013-1519 · Red Hat · Red Hat Enterprise Virtualization Manager

CVE-2012-0861

·

Publicado

2013-01-04

·

Atualizado

2023-02-13

CVSS v2.0

6.8

Média

VetorAV:A/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Virtualization Manager (RHEV-M) versions prior to 3.1
Description The issue concerns the use of the -k curl parameter by the vds installer when adding a host, which prevents SSL certificates from being validated. This allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Recommendations For versions prior to 3.1, update to version 3.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0861
RHSA-2012:1505
RHSA-2012:1506
RHSA-2012:1508

Produtos afetados

Red Hat Enterprise Virtualization Manager