Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yedidyah Bar David

Pesquisador deRed Hat
#31901de 53,638
7.9CVSS total
Vulnerabilidades · 2
Baixa
1
Média
1
PT-2019-6945
4.6
2019-11-01
Ovirt · Ovirt Engine · CVE-2013-4367
**Name of the Vulnerable Software and Affected Versions** ovirt-engine version 3.2 **Description** The issue arises from an upstream kernel change affecting how python's os.chmod() works when passed a mode of '-1', resulting in certain files being created world-writeable on Linux kernel 3.1 and newer. **Recommendations** For ovirt-engine version 3.2, consider modifying the file creation process to explicitly set the desired permissions, avoiding the use of '-1' as a mode for os.chmod().
PT-2016-6427
3.3
2016-10-03
Red Hat · Red Hat Enterprise Virtualization · CVE-2016-5432
**Name of the Vulnerable Software and Affected Versions** Red Hat Enterprise Virtualization (RHEV) Engine version 4.0 **Description** The issue allows local users to obtain sensitive database provisioning information. This is achieved by reading log files, specifically those generated by the ovirt-engine-provisiondb utility. **Recommendations** For Red Hat Enterprise Virtualization (RHEV) Engine version 4.0, consider restricting access to log files generated by the ovirt-engine-provisiondb utility to minimize the risk of sensitive information disclosure.