Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=604752 | |
https://rhn.redhat.com/errata/RHSA-2010-0476.html | Patch Vendor Advisory |
http://securitytracker.com/id?1024137 | |
http://www.securityfocus.com/bid/41044 | |
https://rhn.redhat.com/errata/RHSA-2010-0473.html | Patch Vendor Advisory |
Configurations
Information
Published : 2010-06-24 10:30
Updated : 2010-06-24 21:00
NVD link : CVE-2010-2223
Mitre link : CVE-2010-2223
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
redhat
- enterprise_virtualization_hypervisor